Tenda CH22 editFileName formeditFileName command injection
33Vexday Risk Score
Sem sinal de exploração. Ela tem prova de conceito pública.
ssvc Attendcvss 5.3epss 1.1%
probabilidade de exploração
1.1%top 38% das CVEs
exploração observada
nãonenhuma fonte reporta
1 exploit(s) público(s)
A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formeditFileName of the file /goform/editFileName. The manipulation of the argument editNameMit results in command injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P
Produtos afetados
Tenda · CH22PoCs públicas encontradas — 1
cve_referencecandle-throne-f75.notion.site/Tenda-CH22-formeditFileName-396df0aa1185804c9dcff01778515d32não verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.