First published: Fri Feb 04 2022(Updated: )
Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formSetDeviceName. This vulnerability allows attackers to cause a Denial of Service (DoS) via the devName parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tenda Ax3 Firmware | =16.03.12.10_cn | |
Tenda AX3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-24160 is a vulnerability found in Tenda AX3 v16.03.12.10_CN firmware that allows attackers to cause a denial of service (DoS) through a stack overflow in the function formSetDeviceName.
CVE-2022-24160 has a severity rating of 7.5, which indicates a high severity vulnerability.
The Tenda AX3 firmware version 16.03.12.10_CN is affected by CVE-2022-24160.
CVE-2022-24160 can be exploited by sending a specially crafted devName parameter, which triggers a stack overflow in the formSetDeviceName function.
No, Tenda AX3 devices are not vulnerable to CVE-2022-24160.