Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-21178


An os command injection vulnerability exists in the confsrv ucloud_add_new_node functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a malicious packet to trigger this vulnerability.


Published

2022-08-05T22:15:09.063

Last Modified

2024-11-21T06:44:02.583

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-78
  • Type: Primary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System tcl linkhub_mesh_wifi_ac1200 ms1g_00_01.00_14 Yes
Hardware tcl linkhub_mesh_wifi_ac1200 - No

References