Buffer Overflow Vulnerability in Tenda AC6 Router
CVE-2022-45644

7.5HIGH

Key Information:

Vendor
Tenda
Vendor
CVE Published:
2 December 2022

Summary

A buffer overflow vulnerability has been identified in the Tenda AC6 router, specifically within the formSetClientState function. This vulnerability occurs when the deviceId parameter is improperly handled, potentially allowing attackers to exploit the buffer overflow and manipulate device configurations. If exploited, this flaw could lead to unauthorized access or control over the affected device, raising significant security concerns for users.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.