Critical severity9.8NVD Advisory· Published Aug 12, 2022· Updated Jun 17, 2026
CVE-2022-35555
CVE-2022-35555
Description
A command injection vulnerability exists in /goform/exeCommand in Tenda W6 V1.0.0.9(4122), which allows attackers to construct cmdinput parameters for arbitrary command execution.
Affected products
3- cpe:2.3:o:tenda:w6_firmware:1.0.0.9\(4122\):*:*:*:*:*:*:*
- Tenda/W6description
Patches
Vulnerability mechanics
References
1- github.com/ilovekeer/IOT/blob/main/Tenda/W6/Injection/exeCommand/README.mdnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.