Security Advisory

CVE-2022-24171

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-02-04 01:32:57
Last updated 2024-08-03 04:07:01
Assigner mitre
State PUBLISHED

Description

Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetPppoeServer. This vulnerability allows attackers to execute arbitrary commands via the pppoeServerIP, pppoeServerStartIP, and pppoeServerEndIP parameters.