PT-2022-12486 · Tenda · Tenda Routers G3+1

Published

2022-02-04

·

Updated

2022-07-12

·

CVE-2021-45987

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tenda routers G1 and G3 version 15.11.0.17(9502) CN
Description A command injection issue was discovered in the function formSetNetCheckTools, allowing attackers to execute arbitrary commands via the hostName parameter.
Recommendations For Tenda routers G1 and G3 version 15.11.0.17(9502) CN, consider disabling the formSetNetCheckTools function until a patch is available. Restrict access to the hostName parameter in the affected API endpoint to minimize the risk of exploitation.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-45987

Affected Products

Tenda Routers G1
Tenda Routers G3