References https://nvd.nist.gov/vuln/detail/CVE-2022-34595 https://avd.aliyun.com/detail?id=AVD-2022-34595 https://www.cve.org/CVERecord?id=CVE-2022-34595 https://osv.dev/vulnerability/CVE-2022-34595 https://cve.imfht.com/detail/CVE-2022-34595?lang=en https://access.redhat.com/security/cve/cve-2022-34595 https://github.com/zhefox/Tenda_AX1803_command_injection https://dbugs.ptsecurity.com/vulnerability/PT-2022-22226
Related VulnerabilitiesPoCCVE-2026-62382: PasswordPusher v1.45.11-v2.9.5 - Unauthenticated Anonymous Push Deletion via Ownership BypassGitea /api/v1/repos/diffpatch 代码执行漏洞(CVE-2026-60004)Flowise /api/v1/loginmethod 未授权访问漏洞(CVE-2026-56270)PoCCVE-2022-1281: Photo Gallery WordPress v1.6.3 - SQL InjectionPoCbentoml-open-redirect: BentoML v1.3.9 - Open RedirectKestra /api/v1/main/flows/configs 命令执行漏洞(CVE-2026-53576)Langflow /api/v1/custom_component 代码执行漏洞(CVE-2024-37014)Flowise /api/v1/chatflows 文件上传漏洞(CVE-2025-71334)Open WebUI /api/v1/retrieval/process/web 服务器端请求伪造漏洞(CVE-2026-70485)Gogs /api/v1/orgs/:orgname/teams 信息泄露漏洞(CVE-2026-52815)大华ICC智能物联网管理平台 /evo-runs/v1.0/receive/response/file 文件读取漏洞Datart /api/v1/users/login 默认口令漏洞WordPress /batch/v1 权限绕过漏洞(CVE-2026-60137/CVE-2026-63030)