Stack Overflow Vulnerability Found in Tenda AX3 Router
CVE-2022-24146

7.5HIGH

Key Information:

Vendor

Tenda

Vendor
CVE Published:
4 February 2022

What is CVE-2022-24146?

A stack overflow vulnerability exists in the Tenda AX3 router, specifically in the function formSetQosBand. This flaw can be exploited by attackers to trigger a Denial of Service (DoS) condition through manipulation of the list parameter. When successfully exploited, this vulnerability may render the router inoperable, disrupting network services for affected users.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2022-24146 : Stack Overflow Vulnerability Found in Tenda AX3 Router