Critical severity9.8NVD Advisory· Published Feb 4, 2022· Updated Jun 17, 2026
CVE-2022-24168
CVE-2022-24168
Description
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetIpGroup. This vulnerability allows attackers to execute arbitrary commands via the IPGroupStartIP and IPGroupEndIP parameters.
Affected products
5- cpe:2.3:o:tendacn:g1_firmware:15.11.0.17\(9502\)_cn:*:*:*:*:*:*:*
- cpe:2.3:o:tendacn:g3_firmware:15.11.0.17\(9502\)_cn:*:*:*:*:*:*:*
- Tenda/G1 and G3description
Patches
Vulnerability mechanics
References
1- github.com/pjqwudi/my_vuln/blob/main/Tenda/vuln_37/37.mdnvdBroken LinkExploitThird Party Advisory
News mentions
0No linked articles in our index yet.