CVE-2022-24161: High severity Tenda AX3 firmware vulnerability
Published Feb 4, 2022
·Updated
Tenda AX3 v16.03.12.10CN was discovered to contain a heap overflow in the function GetParentControlInfo. This vulnerability allows attackers to cause a Denial of Service (DoS) via the mac parameter.
Affected Software
2 affected components
Tenda AX3 firmware=16.03.12.10_cn
Tenda AX3
Event History
Feb 4, 2022
CVE Published
via MITRE·01:33 AM
Data Sourced
via MITRE·01:33 AM
Description
Frequently Asked Questions
1
What is CVE-2022-24161?
CVE-2022-24161 is a vulnerability found in Tenda AX3 v16.03.12.10_CN firmware that allows attackers to cause a Denial of Service (DoS) via the mac parameter.
2
How severe is CVE-2022-24161?
CVE-2022-24161 has a severity score of 7.5, which is considered high.
3
How can I fix CVE-2022-24161?
To fix CVE-2022-24161, it is recommended to update the Tenda AX3 firmware to a version that contains the necessary security patches.
4
What is the affected software version of CVE-2022-24161?
The affected software version of CVE-2022-24161 is Tenda AX3 firmware version 16.03.12.10_CN.
5
What is the Common Weakness Enumeration (CWE) ID associated with CVE-2022-24161?
CVE-2022-24161 is associated with CWE-787, which is a weakness related to Out-of-bounds Write.