Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-40843

43
FAUCET Score

CVE-2022-40843 is an improper authorization/session management vulnerability affecting Tenda AC1200 V-W15Ev2 V15.11.0.10(1576) routers, allowing authenticated attackers to bypass the login page. This flaw enables access to the router's syslog.log file, which contains the administrator's MD5 password. Rated Medium (CVSS 4.9), the vulnerability has a network attack vector with low complexity, leading to high confidentiality impact. There is no evidence of active exploitation, though a Nuclei template exists for detection; community discussion and media coverage are minimal.

Impacted Technologies

VendorProductVersion(s)CPE
15.11.0.10\(1576\)CPE matchmatch criteria
cpe:2.3:o:tenda:w15e_firmware:15.11.0.10\(1576\):*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.9MEDIUM

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
1.2
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
28.80%
Probability of exploitation in next 30 days
EPSS Percentile
97.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Nuclei: CVE-2022-40843 · Nov 3, 2022
This CVE's current EPSS score of 0.2880 is in the 100th percentile among its peer group of 3,565 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

boschko.ca / tenda_ac1200_router
ExploitTechnical DescriptionThird Party Advisory