CVE-2022-25459: Critical severity tenda ac6 firmware vulnerability
Published Mar 18, 2022
·Updated
Tenda AC6 v15.03.05.09multi was discovered to contain a stack overflow via the S1 parameter in the SetSysTimeCfg function.
Affected Software
2 affected components
Tenda Ac6 Firmware=15.03.05.09
Tenda AC6
Event History
Mar 18, 2022
CVE Published
via MITRE·08:53 PM
Data Sourced
via MITRE·08:53 PM
Description
Frequently Asked Questions
1
What is CVE-2022-25459?
CVE-2022-25459 is a vulnerability found in Tenda AC6 v15.03.05.09_multi firmware that allows for a stack overflow through the S1 parameter in the SetSysTimeCfg function.
2
How severe is CVE-2022-25459?
CVE-2022-25459 has a severity rating of 9.8, which is considered critical.
3
Which software versions are affected by CVE-2022-25459?
Tenda AC6 v15.03.05.09_multi firmware is affected by CVE-2022-25459.
4
How can CVE-2022-25459 be exploited?
CVE-2022-25459 can be exploited by providing a malicious value to the S1 parameter in the SetSysTimeCfg function.
5
Is there a fix available for CVE-2022-25459?
At the moment, there is no known fix available for CVE-2022-25459. It is recommended to follow the latest security updates from Tenda for any available patches or mitigation strategies.