Record summary

CVE-2022-42233 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

Tenda 11N with firmware version V5.07.33_cn suffers from an Authentication Bypass vulnerability.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated May 8, 2025 · Source: CVE List

Nuclei templates

1
ProjectDiscoveryCRITICALTenda 11N - Authentication BypassCVSS 9.8

Tenda 11N with firmware version V5.07.33_cn contains an authentication bypass vulnerability. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.

Impact

Unauthenticated attackers can bypass authentication by setting an admin cookie to gain full administrative access to Tenda 11N routers, enabling complete device configuration changes and network compromise.

Remediation

Apply the latest firmware update provided by Tenda to fix the authentication bypass vulnerability (CVE-2022-42233).

WeaknessesCWE-287
AuthorsFor3stCo1d
Template tagscvecve2022tendaauth-bypassrouteriotvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:o:tenda:11n_firmware:5.07.33_cn:*:*:*:*:*:*:*
Shodan: http.title:"Tenda 11N"
Shodan: http.title:"tenda 11n"
FOFA: product=="Tenda-11N-Wireless-AP"
FOFA: product=="tenda-11n-wireless-ap"
FOFA: title="tenda 11n"
Google: intitle:"tenda 11n"

Source: ProjectDiscovery

References

2