CVE-2022-24149: High severity Tenda AX3 firmware vulnerability
Published Feb 4, 2022
·Updated
Tenda AX3 v16.03.12.10CN was discovered to contain a stack overflow in the function fromSetWirelessRepeat. This vulnerability allows attackers to cause a Denial of Service (DoS) via the wpapskcrypto parameter.
Affected Software
2 affected components
Tenda AX3 firmware=16.03.12.10_cn
Tenda AX3
Event History
Feb 4, 2022
CVE Published
via MITRE·01:33 AM
Data Sourced
via MITRE·01:33 AM
Description
Frequently Asked Questions
1
What is CVE-2022-24149?
CVE-2022-24149 is a vulnerability found in Tenda AX3 v16.03.12.10_CN firmware that allows attackers to cause a Denial of Service (DoS) via a stack overflow in the function fromSetWirelessRepeat.
2
What is the severity of CVE-2022-24149?
The severity of CVE-2022-24149 is high with a CVSS score of 7.5.
3
How can CVE-2022-24149 be exploited?
CVE-2022-24149 can be exploited by attackers using the wpapsk_crypto parameter to trigger the stack overflow.
4
What is the affected software of CVE-2022-24149?
The affected software is Tenda AX3 v16.03.12.10_CN firmware.
5
Is Tenda AX3 vulnerable to CVE-2022-24149?
Yes, Tenda AX3 v16.03.12.10_CN firmware is vulnerable to CVE-2022-24149.