Command Injection Vulnerability in Tenda W30E Router
CVE-2022-45506
9.8CRITICAL
What is CVE-2022-45506?
The Tenda W30E router is vulnerable to a command injection flaw that arises from improper handling of the fileNameMit parameter within the /goform/delFileName endpoint. A malicious actor can exploit this vulnerability to execute arbitrary commands on the affected device, potentially leading to unauthorized file deletions and other detrimental actions against the router’s filesystem.