vendor:
Tenda HG6
by:
LiquidWorm
7.5
CVSS
HIGH
Remote Command Injection
78
CWE
Product Name: Tenda HG6
Affected Version From: Firmware version: 3.3.0-210926, Software version: v1.1.0, Hardware Version: v1.0, Check Version: TD_HG6_XPON_TDE_ISP
Affected Version To:
Patch Exists: NO
Related CWE:
CPE: a:tenda_technology:hg6_firmware:3.3.0-210926, cpe:/a:tenda_technology:hg6_software:v1.1.0
Platforms Tested:
2022
Tenda HG6 v3.3.0 – Remote Command Injection
The application suffers from an authenticated OS command injection vulnerability. This can be exploited to inject and execute arbitrary shell commands through the 'pingAddr' and 'traceAddr' HTTP POST parameters in formPing, formPing6, formTracert and formTracert6 interfaces.
Mitigation:
Update to a fixed firmware version.