CVE-2022-35555 is a critical command injection vulnerability found in the Tenda W6 V1.0.0.9(4122) wireless access point. This vulnerability exists in the /goform/exeCommand endpoint, where attackers can exploit the cmdinput parameter to execute arbitrary commands on the device. The vulnerability allows remote attackers to gain control over the device, potentially leading to unauthorized access, data exfiltration, or further network compromise.
The vulnerability was reported by multiple sources, including the National Vulnerability Database (NVD), MITRE, Tenable, GitHub, OpenCVE, VulDB, Cloud Defense, and FortiGuard Labs. Despite its critical nature, the SUSE CVE-2022-35555 was marked as "REJECT" by its CNA, indicating it was determined not to be a security issue. However, other sources have confirmed its existence and potential impact.
Attackers can exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable endpoint. The exploitation does not require authentication, making it easier for attackers to target exposed devices. Once exploited, attackers can run arbitrary commands with the same privileges as the web server, which could lead to complete system compromise.
The criticality of this vulnerability is high due to the ease of exploitation and the potential impact on affected systems. Network administrators and security professionals should prioritize addressing this vulnerability to prevent potential attacks.
|