CVE-2022-30023 is a critical command injection vulnerability affecting the Tenda ONT GPON AC1200 Dual band WiFi HG9 v1.0.1, specifically within its Ping function. With a CVSS score of 8.8 (HIGH), this flaw allows an authenticated attacker to execute arbitrary commands remotely with low complexity, leading to high impact on confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, the vulnerability has garnered significant community discussion and media coverage, indicating high awareness, though no public exploit intelligence (Metasploit, Nuclei, ExploitDB) is currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.1CPE matchmatch criteria | cpe:2.3:o:tenda:hg9_firmware:1.0.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.