CVE-2022-24143: High severity Tenda AX3 firmware vulnerability
Published Feb 4, 2022
·Updated
Tenda AX3 v16.03.12.10CN and AX12 22.03.01.2CN was discovered to contain a stack overflow in the function formfastsettingwifiset. This vulnerability allows attackers to cause a Denial of Service (DoS) via the timeZone parameter.
Affected Software
4 affected components
Tenda AX3 firmware=16.03.12.10_cn
Tenda AX3
Tenda Ax12 Firmware=22.03.01.2_cn
Tenda AX12
Event History
Feb 4, 2022
CVE Published
via MITRE·01:33 AM
Data Sourced
via MITRE·01:33 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this Tenda AX3 and AX12 vulnerability?
The vulnerability ID is CVE-2022-24143.
2
What is the severity level of CVE-2022-24143?
The severity level of CVE-2022-24143 is high, with a severity value of 7.5.
3
What is the affected software for CVE-2022-24143?
The affected software for CVE-2022-24143 is Tenda AX3 firmware version 16.03.12.10_CN and Tenda AX12 firmware version 22.03.01.2_CN.
4
What is the impact of CVE-2022-24143?
CVE-2022-24143 allows attackers to cause a Denial of Service (DoS) via the timeZone parameter.
5
Is Tenda AX3 and AX12 vulnerable to CVE-2022-24143?
Tenda AX3 and AX12 are vulnerable to CVE-2022-24143 if they are running the affected firmware versions.