Buffer Overflow Vulnerability in TCL LinkHub Mesh Wifi Product
CVE-2022-23399
8.8HIGH
What is CVE-2022-23399?
A stack-based buffer overflow vulnerability is present in the confsrv set_port_fwd_rule functionality of TCL LinkHub Mesh Wifi devices. This vulnerability can be exploited by sending specifically crafted network packets, which can lead to overflow of the stack memory, potentially allowing an attacker to execute arbitrary code or disrupt service.
Affected Version(s)
LinkHub Mesh Wifi MS1G_00_01.00_14
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
CVSS V3.0
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved