CVE-2022-37814Out-of-bounds Write in Ac1206 Firmware

Severity
9.8CRITICALNVD
EPSS
0.5%
top 35.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 25
Latest updateAug 26

Description

Tenda AC1206 V15.03.06.23 was discovered to contain multiple stack overflows via the deviceMac and the device_id parameters in the function addWifiMacFilter.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

NVDtenda/ac1206_firmware15.03.06.23

🔴Vulnerability Details

2
GHSA
GHSA-489q-9jv9-92q4: Tenda AC1206 V152022-08-26
CVEList
CVE-2022-37814: Tenda AC1206 V152022-08-25
CVE-2022-37814 — Out-of-bounds Write in Tenda | cvebase