Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-35555


A command injection vulnerability exists in /goform/exeCommand in Tenda W6 V1.0.0.9(4122), which allows attackers to construct cmdinput parameters for arbitrary command execution.


Published

2022-08-12T15:15:15.647

Last Modified

2024-11-21T07:11:19.623

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System tenda w6_firmware 1.0.0.9\(4122\) Yes
Hardware tenda w6 - No

References