Command Injection Vulnerabilities in Tenda AC1200 Router by Tenda
CVE-2022-41396

7.8HIGH

Key Information:

Vendor
Tenda
Vendor
CVE Published:
15 November 2022

Summary

The Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) is found to have multiple command injection vulnerabilities affecting the setIPsecTunnelList function. These vulnerabilities arise through unsanitized input in the IPsecLocalNet and IPsecRemoteNet parameters, allowing remote attackers to execute arbitrary commands on the affected system, potentially leading to severe disruptions in network security.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.