Tenda CH22 editFileName formeditFileName command injection
33Vexday Risk Score
Sin señal de explotación. Ella tiene prueba de concepto pública.
ssvc Attendcvss 5.3epss 1.1%
probabilidad de explotación
1.1%top 38% de las CVE
explotación observada
noninguna fuente lo reporta
1 exploit(s) público(s)
A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formeditFileName of the file /goform/editFileName. The manipulation of the argument editNameMit results in command injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P
Productos afectados
Tenda · CH22PoCs públicas encontradas — 1
cve_referencecandle-throne-f75.notion.site/Tenda-CH22-formeditFileName-396df0aa1185804c9dcff01778515d32no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.