Tenda HG6 3.3.0 Remote Command Injection

Discussion in 'News Aggregator' started by Packet Storm, 4 May 2022.

  1. Packet Storm

    Packet Storm Guest

    Tenda HG6 version 3.3.0 suffers from a remote command injection vulnerability. It can be exploited to inject and execute arbitrary shell commands through the pingAddr and traceAddr HTTP POST parameters in formPing, formPing6, formTracert and formTracert6 interfaces.

    Continue reading...
     

Share This Page

Loading...