CVE-2022-24142: High severity Tenda AX3 firmware vulnerability
Tenda AX3 v16.03.12.10CN was discovered to contain a stack overflow in the function formSetFirewallCfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via the firewallEn parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-24142?
CVE-2022-24142 is a vulnerability found in Tenda AX3 v16.03.12.10_CN firmware that allows attackers to cause a Denial of Service (DoS) via a stack overflow in the function formSetFirewallCfg.
How severe is CVE-2022-24142?
CVE-2022-24142 has a severity level of high with a score of 7.5.
Which software versions are affected by CVE-2022-24142?
The Tenda AX3 firmware version 16.03.12.10_CN is affected by CVE-2022-24142.
How can attackers exploit CVE-2022-24142?
Attackers can exploit CVE-2022-24142 by sending malicious input to the firewallEn parameter, causing a stack overflow and resulting in a Denial of Service (DoS) attack.
Is Tenda AX3 vulnerable to CVE-2022-24142?
Yes, Tenda AX3 firmware version 16.03.12.10_CN is vulnerable to CVE-2022-24142.