CVE-2022-24154: High severity Tenda AX3 firmware vulnerability
Tenda AX3 v16.03.12.10CN was discovered to contain a stack overflow in the function formSetRebootTimer. This vulnerability allows attackers to cause a Denial of Service (DoS) via the rebootTime parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-24154?
CVE-2022-24154 is a vulnerability found in Tenda AX3 v16.03.12.10_CN firmware, which allows attackers to cause a Denial of Service (DoS) via the rebootTime parameter.
How severe is CVE-2022-24154?
CVE-2022-24154 has a severity rating of 7.5 (high).
How can the CVE-2022-24154 vulnerability be exploited?
The CVE-2022-24154 vulnerability can be exploited by sending malicious input in the rebootTime parameter.
Is Tenda AX3 v16.03.12.10_CN the only affected software?
No, Tenda Ax3 Firmware version 16.03.12.10_cn is the affected software, but Tenda AX3 hardware is not vulnerable.
Is there a fix available for CVE-2022-24154?
At the time of this report, no official fix has been released for CVE-2022-24154. It is recommended to update to the latest firmware version when it becomes available.