Critical severity9.8NVD Advisory· Published Feb 4, 2022· Updated Jun 17, 2026
CVE-2022-24148
CVE-2022-24148
Description
Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the function mDMZSetCfg. This vulnerability allows attackers to execute arbitrary commands via the dmzIp parameter.
Affected products
3- cpe:2.3:o:tenda:ax3_firmware:16.03.12.10_cn:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- github.com/pjqwudi/my_vuln/blob/main/Tenda/vuln_14/14.mdnvdBroken LinkExploitThird Party Advisory
News mentions
0No linked articles in our index yet.