Command Injection Vulnerabilities in Tenda AC1200 Router by Tenda
CVE-2022-41396
7.8HIGH
What is CVE-2022-41396?
The Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) is found to have multiple command injection vulnerabilities affecting the setIPsecTunnelList function. These vulnerabilities arise through unsanitized input in the IPsecLocalNet and IPsecRemoteNet parameters, allowing remote attackers to execute arbitrary commands on the affected system, potentially leading to severe disruptions in network security.