Cross Site Request Forgery in Tenda i22 by Tenda
CVE-2022-45667

6.5MEDIUM

Key Information:

Vendor
Tenda
Vendor
CVE Published:
2 December 2022

Summary

The Tenda i22 V1.0.0.3(4687) is susceptible to a Cross Site Request Forgery (CSRF) attack via the fromSysToolRestoreSet function. This vulnerability could allow an attacker to exploit the device by sending unauthorized requests, potentially compromising its configuration and controls. Users should apply security best practices and monitor for unusual activity to mitigate risks.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.