CVE-2022-27079: Tenda m3 Firmware

Critical severity, CVSS 9.8. EPSS: 2.6% chance of exploitation in the next 30 days.

Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setPicListItem.

Affected products

  • Tenda m3 Firmware: version 1.0.0.12(4856) only

Published 2022-03-24. Last modified 2026-06-17.