Stack Overflow Vulnerability in Tenda AX12 Router's HTTP Service
CVE-2022-28561
9.8CRITICAL
What is CVE-2022-28561?
A stack overflow vulnerability has been identified in the /goform/setMacFilterCfg function of the httpd service in Tenda's AX12 router. Exploiting this vulnerability allows attackers to craft a specific payload that can lead to unauthorized access, enabling them to establish a stable shell on the device. This could potentially lead to further unauthorized actions on the network, raising serious security concerns for users relying on the affected router model.