CVE-2022-37861
Last modified
CVE-2022-37861 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. There is a remote code execution (RCE) vulnerability in Tenhot TWS-100 V4.0-201809201424 router device. It is necessary to know that the device account password is allowed to escape the execution system command through the network tools in the network diagnostic component.. EPSS estimates a 1.77% chance of exploitation in the next 30 days.
Description
There is a remote code execution (RCE) vulnerability in Tenhot TWS-100 V4.0-201809201424 router device. It is necessary to know that the device account password is allowed to escape the execution system command through the network tools in the network diagnostic component.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tenhot | Tws-100 Firmware | 4.0-201809201424 |
References
- http://www.tenhot.net/html/pro/wgzly/111704.htmlVendor Advisory
- https://gist.github.com/ox01024/784894c27213c5a765b5c8f8375db256Exploit, Third Party Advisory
- http://www.tenhot.net/html/pro/wgzly/111704.htmlVendor Advisory
- https://gist.github.com/ox01024/784894c27213c5a765b5c8f8375db256Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-37861?
How severe is CVE-2022-37861?
How do I fix CVE-2022-37861?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-37842In TOTOLINK A860R V4.1.2cu.5182_B20201027, the parameters in…9.8
- CVE-2022-37843In TOTOLINK A860R V4.1.2cu.5182_B20201027 in cstecgi.cgi, th…9.8
- CVE-2022-3785A vulnerability, which was classified as critical, has been …7.8
- CVE-2022-37857bilde2910 Hauk v1.6.1 requires a hardcoded password which by…7.5
- CVE-2022-3786A buffer overrun can be triggered in X.509 certificate verif…7.5
- CVE-2022-37860The web configuration interface of the TP-Link M7350 V3 with…9.8
- CVE-2022-37864A vulnerability has been identified in Solid Edge (All Versi…7.8
- CVE-2022-37865With Apache Ivy 2.4.0 an optional packaging attribute has be…9.1
- CVE-2022-37866When Apache Ivy downloads artifacts from a repository it sto…7.5
- CVE-2022-3787A vulnerability was found in the device-mapper-multipath. Th…7.8
- CVE-2022-37877A vulnerability in the ClearPass OnGuard macOS agent could a…7.8
- CVE-2022-37878Vulnerabilities in the ClearPass Policy Manager web-based ma…7.2
Are you affected by CVE-2022-37861?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
