CVE-2022-40869Out-of-bounds Write in Ac15 Firmware

Severity
9.8CRITICALNVD
EPSS
0.5%
top 35.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 23
Latest updateSep 25

Description

Tenda AC15 and AC18 routers V15.03.05.19 contain stack overflow vulnerabilities in the function fromDhcpListClient with a combined parameter "list*" ("%s%d","list").

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

NVDtendacn/ac15_firmware15.03.05.19
NVDtendacn/ac18_firmware15.03.05.19

🔴Vulnerability Details

2
GHSA
GHSA-669q-4gjm-8895: Tenda AC15 and AC18 routers V152022-09-25
CVEList
CVE-2022-40869: Tenda AC15 and AC18 routers V152022-09-23
CVE-2022-40869 — Out-of-bounds Write in Ac15 Firmware | cvebase