Stack Overflow Vulnerability in Tenda W6-S Router
CVE-2022-45503

7.5HIGH

Key Information:

Vendor
Tenda
Vendor
CVE Published:
8 December 2022

Summary

A stack overflow vulnerability has been identified in the Tenda W6-S router, specifically in version v1.0.0.4(510). An attacker can exploit this vulnerability through improperly validated input to the linkEn parameter at the /goform/setAutoPing endpoint, potentially leading to arbitrary code execution and unauthorized access. Users are recommended to consider patching or updating their devices to mitigate risks associated with this vulnerability.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.