Stack Overflow Vulnerability in Tenda Routers G1 and G3
CVE-2022-24172

7.5HIGH

Key Information:

Vendor
Tenda
Vendor
CVE Published:
4 February 2022

Summary

A stack overflow vulnerability has been identified in Tenda routers G1 and G3. Specifically, this issue resides in the function formAddDhcpBindRule, where the addDhcpRules parameter can be exploited by attackers to trigger a Denial of Service (DoS). This flaw can render the affected devices unresponsive, compromising the integrity and availability of network services for users. It is crucial for users of the affected router models to apply appropriate security measures to mitigate potential risks.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.