Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Tenda CH22 formcreateFileName command injection
Vulnerability Description
A vulnerability has been found in Tenda CH22 1.0.0.1. The affected element is the function formcreateFileName of the file /goform/formcreateFileName. The manipulation of the argument fileNameMit leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Vulnerability Type
在命令中使用的特殊元素转义处理不恰当(命令注入)
Vulnerability Title
Tenda ch22 firmware 输入验证错误漏洞
Vulnerability Description
Tenda ch22 firmware是中国Tenda公司的一款路由器固件。 Tenda ch22 firmware 1.0.0.1版本存在安全漏洞,该漏洞源于/goform/formcreateFileName文件中的formcreateFileName函数对fileNameMit参数操作不当,导致命令注入,攻击者可远程利用。
CVSS Information
N/A
Vulnerability Type
N/A