Stack Overflow Vulnerability in Tenda M3 by Tenda
CVE-2022-38570
7.5HIGH
Summary
A stack overflow vulnerability has been identified in Tenda M3 version 1.0.0.12(4856). This flaw is present in the function formDelPushedAd, which processes the adPushUID parameter. Attackers can exploit this vulnerability to trigger a Denial of Service (DoS), compromising the availability of the device. For more details and potential mitigations, check the reference below.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved