Stack Overflow Vulnerability in Tenda TX3 Router by Tenda
CVE-2022-43024
9.8CRITICAL
Summary
The Tenda TX3 Router is affected by a stack overflow vulnerability that can be triggered through the 'list' parameter at the /goform/SetVirtualServerCfg endpoint. This flaw can be exploited by an attacker to execute arbitrary code, potentially compromising the integrity and confidentiality of the device. Users of the affected versions are strongly advised to update their firmware to mitigate the risk associated with this vulnerability.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved