CVE-2022-30023High· 8.8▾ Midnight⚠ Exploited in the wildPoC availableTenda ONT GPON AC1200 Dual band WiFi HG9 v1.0.1 is vulnerable to Command Injection via the Ping function.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 48.4 · likelihood 7.8 · exploitation 18
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 6.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
44%
1 GitHub repo
Tenda ONT GPON AC1200 Dual band WiFi HG9 v1.0.1 is vulnerable to Command Injection via the Ping function.
hg9_firmware = 1.0.1Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-8265Medium· 4.7A security vulnerability has been detected in Tenda AC6 15.03.06.23
CVE-2026-8264Medium· 6.3A weakness has been identified in Tenda AC6 15.03.06.23
CVE-2026-8259Medium· 4.7A vulnerability has been found in Tenda AC6 2.0/15.03.06.23
CVE-2026-86167Critical· 9.9A vulnerability was identified in Tenda HG10 300001138
CVE-2026-86151Critical· 9.1A vulnerability was detected in Tenda CP3 27.5.57.101
CVE-2018-11138Critical· 9.8The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.