Cyber Resilience

CVE-2022-46538

CriticalPublic PoCRCE

Published: 20 December 2022

Published
20 December 2022
Modified
16 April 2025
KEV Added
Patch
CVSS Score v3.1 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.1836 95.4th percentile
Risk Priority 31 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2022-46538 is a critical-severity OS Command Injection (CWE-78) vulnerability in Tenda F1203 Firmware. Its CVSS base score is 9.8 (Critical).

Operationally, ranked in the top 4.6% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

Deeper analysis

Tenda F1203 firmware version 2.0.1.6 contains an OS command injection vulnerability, tracked as CWE-78, in the mac parameter processed by the /goform/WriteFacMac endpoint. The flaw received a CVSS 3.1 base score of 9.8, reflecting network attack vector, low attack complexity, and no required authentication or user interaction.

Remote unauthenticated attackers can supply a crafted mac value to the web interface and execute arbitrary operating-system commands on the device, resulting in complete compromise of confidentiality, integrity, and availability. The two reference URLs point to the same public proof-of-concept repository that demonstrates the injection but contain no vendor advisory, patch information, or mitigation guidance. The associated EPSS score has remained flat at 0.1836 with no material rise after disclosure.

EU & UK References

Vulnerability details

Tenda F1203 V2.0.1.6 was discovered to contain a command injection vulnerability via the mac parameter at /goform/WriteFacMac.

CWE(s)

Related Threats

No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.

Affected Assets

tenda
f1203 firmware
2.0.1.6

Mitigating Controls

Likely Mitigating Controls AI

Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.

addresses: CWE-78

Platform-independent apps typically execute inside a managed runtime or sandbox that restricts direct OS command execution, reducing the ability to exploit OS command injection.

addresses: CWE-78

Validates inputs to block special elements that would alter OS command execution.

References