CVE-2022-41396

HIGH

Tenda AC1200 Router - Command Injection

Title source: llm
STIX 2.1

Description

Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain multiple command injection vulnerabilities in the function setIPsecTunnelList via the IPsecLocalNet and IPsecRemoteNet parameters.

References (2)

Core 2
Core References
Exploit, Technical Description, Third Party Advisory
https://boschko.ca/tenda_ac1200_router
Exploit, Third Party Advisory
https://boschko.ca/tenda_ac1200_router/

Scores

CVSS v3 7.8
EPSS 0.0163
EPSS Percentile 82.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (1)
tenda/w15e_firmware 15.11.0.10\(1576\)
Published Nov 15, 2022
Tracked Since Feb 18, 2026