First published: Fri Mar 18 2022(Updated: )
Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the ntpserver parameter in the SetSysTimeCfg function.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tenda Ac9 Firmware | =15.03.2.21 | |
Tenda AC9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-25440 is a vulnerability discovered in Tenda AC9 v15.03.2.21 that allows for a stack overflow via the ntpserver parameter in the SetSysTimeCfg function.
CVE-2022-25440 is considered a critical vulnerability with a severity score of 9.8 out of 10.
Tenda AC9 firmware version 15.03.2.21 is affected by CVE-2022-25440.
To fix CVE-2022-25440, it is recommended to update the Tenda AC9 firmware to a non-vulnerable version.
More information about CVE-2022-25440 can be found at the following link: https://github.com/EPhaha/IOT_vuln/tree/main/Tenda/AC9/13