Critical severity9.8NVD Advisory· Published Apr 7, 2022· Updated Jun 17, 2026
CVE-2022-27022
CVE-2022-27022
Description
There is a stack overflow vulnerability in the SetSysTimeCfg() function in the httpd service of Tenda AC9 V15.03.2.21_cn. The attacker can obtain a stable root shell through a constructed payload.
Affected products
3- cpe:2.3:o:tenda:ac9_firmware:15.03.2.21_cn:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- github.com/EPhaha/IOT_vuln/tree/main/Tenda/AC9/14nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.