⚠ Exploited in the wild
Exploitation observed in the wild. Not yet on CISA KEV.

CVE-2022-31446OS Command Injection in Ac18 Firmware

Severity
9.8CRITICALNVD
EPSS
17.7%
top 4.88%
CISA KEV
Not in KEV
Exploit
Exploited in wild
Active exploitation observed
Affected products
Timeline
PublishedJun 14
Latest updateJun 15

Description

Tenda AC18 router V15.03.05.19 and V15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability via the Mac parameter at ip/goform/WriteFacMac.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

NVDtendacn/ac18_firmware15.03.05.05, 15.03.05.19+1

🔴Vulnerability Details

3
GHSA
GHSA-8hqv-xv5w-4q8r: Tenda AC18 router V152022-06-15
CVEList
CVE-2022-31446: Tenda AC18 router V152022-06-14
VulnCheck
Tenda ac18_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2022
CVE-2022-31446 — OS Command Injection in Ac18 Firmware | cvebase