CVE-2022-40862Out-of-bounds Write in Ac15 Firmware

Severity
9.8CRITICALNVD
EPSS
0.5%
top 35.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 23
Latest updateSep 25

Description

Tenda AC15 and AC18 router V15.03.05.19 contains stack overflow vulnerability in the function fromNatStaticSetting with the request /goform/NatStaticSetting

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

NVDtendacn/ac15_firmware15.03.05.19
NVDtendacn/ac18_firmware15.03.05.19

🔴Vulnerability Details

2
GHSA
GHSA-5xm4-48v6-7p2f: Tenda AC15 and AC18 router V152022-09-25
CVEList
CVE-2022-40862: Tenda AC15 and AC18 router V152022-09-23
CVE-2022-40862 — Out-of-bounds Write in Ac15 Firmware | cvebase