CVE-2022-25454: Critical severity tenda ac6 firmware vulnerability
Published Mar 18, 2022
·Updated
Tenda AC6 v15.03.05.09multi was discovered to contain a stack overflow via the loginpwd parameter in the SetFirewallCfg function.
Affected Software
2 affected components
Tenda Ac6 Firmware=15.03.05.09
Tenda AC6
Event History
Mar 18, 2022
CVE Published
via MITRE·08:53 PM
Data Sourced
via MITRE·08:53 PM
Description
Frequently Asked Questions
1
What is CVE-2022-25454?
CVE-2022-25454 is a vulnerability discovered in Tenda AC6 v15.03.05.09_multi firmware that allows for a stack overflow via the loginpwd parameter in the SetFirewallCfg function.
2
How severe is CVE-2022-25454?
CVE-2022-25454 has a severity rating of 9.8 out of 10, making it critical.
3
Which software version of Tenda AC6 is affected by CVE-2022-25454?
The Tenda AC6 firmware version 15.03.05.09 is affected by CVE-2022-25454.
4
How can the vulnerability CVE-2022-25454 be exploited?
The vulnerability CVE-2022-25454 can be exploited by sending a specially crafted value to the loginpwd parameter in the SetFirewallCfg function.
5
Is Tenda AC6 hardware vulnerable to CVE-2022-25454?
No, Tenda AC6 hardware is not vulnerable to CVE-2022-25454.