CVE-2022-37861
Last modified
CVE-2022-37861 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. There is a remote code execution (RCE) vulnerability in Tenhot TWS-100 V4.0-201809201424 router device. It is necessary to know that the device account password is allowed to escape the execution system command through the network tools in the network diagnostic component.. EPSS estimates a 1.77% chance of exploitation in the next 30 days.
Description
There is a remote code execution (RCE) vulnerability in Tenhot TWS-100 V4.0-201809201424 router device. It is necessary to know that the device account password is allowed to escape the execution system command through the network tools in the network diagnostic component.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tenhot | Tws-100 Firmware | 4.0-201809201424 |
References
- http://www.tenhot.net/html/pro/wgzly/111704.htmlVendor Advisory
- https://gist.github.com/ox01024/784894c27213c5a765b5c8f8375db256Exploit, Third Party Advisory
- http://www.tenhot.net/html/pro/wgzly/111704.htmlVendor Advisory
- https://gist.github.com/ox01024/784894c27213c5a765b5c8f8375db256Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-37861?
How severe is CVE-2022-37861?
How do I fix CVE-2022-37861?
Are you affected by CVE-2022-37861?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
