CVE-2022-40876

Severity
9.8CRITICAL
EPSS
4.5%
top 10.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 27
Latest updateOct 28

Description

In Tenda ax1803 v1.0.0.1, the http requests handled by the fromAdvSetMacMtuWan functions, wanSpeed, cloneType, mac, can cause a stack overflow and enable remote code execution (RCE).

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-qwwj-2xhc-x8v6: In Tenda ax1803 v12022-10-28
CVEList
CVE-2022-40876: In Tenda ax1803 v12022-10-27
CVE-2022-40876 (CRITICAL CVSS 9.8) | In Tenda ax1803 v1.0.0.1 | cvebase.io