Stack Overflow Vulnerability in Tenda W30E Router
CVE-2022-45525
7.5HIGH
Summary
The Tenda W30E router is susceptible to a stack overflow vulnerability due to improper handling of the downaction parameter within the /goform/CertListInfo endpoint. This flaw can potentially allow an attacker to derail normal execution flow, leading to denial of service or remote code execution under certain conditions. It underscores the importance of stringent input validation in networking devices to mitigate potential threats.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved