CVE-2022-24159: High severity Tenda AX3 firmware vulnerability
Published Feb 4, 2022
·Updated
Tenda AX3 v16.03.12.10CN was discovered to contain a stack overflow in the function formSetPPTPServer. This vulnerability allows attackers to cause a Denial of Service (DoS) via the startIp and endIp parameters.
Affected Software
2 affected components
Tenda AX3 firmware=16.03.12.10_cn
Tenda AX3
Event History
Feb 4, 2022
CVE Published
via MITRE·01:33 AM
Data Sourced
via MITRE·01:33 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Tenda AX3 stack overflow vulnerability?
The vulnerability ID for this Tenda AX3 stack overflow vulnerability is CVE-2022-24159.
2
What is the severity rating of CVE-2022-24159?
CVE-2022-24159 has a severity rating of 7.5 (high).
3
What is the affected software version of CVE-2022-24159?
The affected software version of CVE-2022-24159 is Tenda Ax3 Firmware version 16.03.12.10_CN.
4
How does CVE-2022-24159 impact Tenda AX3?
CVE-2022-24159 allows attackers to cause a Denial of Service (DoS) on Tenda AX3 devices through the startIp and endIp parameters.
5
Is Tenda AX3 vulnerable to CVE-2022-24159?
Yes, Tenda AX3 devices with the affected firmware version 16.03.12.10_CN are vulnerable to CVE-2022-24159.