Command Injection Vulnerabilities in Tenda AC1200 Router by Tenda
CVE-2022-41396
7.8HIGH
Summary
The Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) is found to have multiple command injection vulnerabilities affecting the setIPsecTunnelList function. These vulnerabilities arise through unsanitized input in the IPsecLocalNet and IPsecRemoteNet parameters, allowing remote attackers to execute arbitrary commands on the affected system, potentially leading to severe disruptions in network security.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved