VYPR
Critical severity9.8NVD Advisory· Published Aug 12, 2022· Updated Jun 17, 2026

CVE-2022-35555

CVE-2022-35555

Description

A command injection vulnerability exists in /goform/exeCommand in Tenda W6 V1.0.0.9(4122), which allows attackers to construct cmdinput parameters for arbitrary command execution.

Affected products

3
  • cpe:2.3:o:tenda:w6_firmware:1.0.0.9\(4122\):*:*:*:*:*:*:*
  • Tenda/W6description
  • Tenda/W6llm-fuzzy
    Range: 1.0.0.9(4122)

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.