CVE-2022-24160: High severity Tenda AX3 firmware vulnerability
Tenda AX3 v16.03.12.10CN was discovered to contain a stack overflow in the function formSetDeviceName. This vulnerability allows attackers to cause a Denial of Service (DoS) via the devName parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-24160?
CVE-2022-24160 is a vulnerability found in Tenda AX3 v16.03.12.10_CN firmware that allows attackers to cause a denial of service (DoS) through a stack overflow in the function formSetDeviceName.
How severe is CVE-2022-24160?
CVE-2022-24160 has a severity rating of 7.5, which indicates a high severity vulnerability.
What software versions are affected by CVE-2022-24160?
The Tenda AX3 firmware version 16.03.12.10_CN is affected by CVE-2022-24160.
How can CVE-2022-24160 be exploited?
CVE-2022-24160 can be exploited by sending a specially crafted devName parameter, which triggers a stack overflow in the formSetDeviceName function.
Is Tenda AX3 vulnerable to CVE-2022-24160?
No, Tenda AX3 devices are not vulnerable to CVE-2022-24160.