Buffer Overflow Vulnerability in Tenda i9 Router
CVE-2022-40103

5.5MEDIUM

Key Information:

Vendor
Tenda
Vendor
CVE Published:
23 September 2022

Summary

The Tenda i9 router version v1.0.0.8(3828) is susceptible to a buffer overflow vulnerability through the formSetAutoPing function. This security flaw allows malicious actors to craft a specific input string that can trigger the vulnerability, potentially leading to a Denial of Service (DoS) condition. As a result, the router may become unresponsive, limiting user access and impacting network reliability. It is crucial for users to implement available security measures and updates to mitigate the risks associated with this vulnerability.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.