CVE-2022-25460: Critical severity tenda ac6 firmware vulnerability
Published Mar 18, 2022
·Updated
Tenda AC6 v15.03.05.09multi was discovered to contain a stack overflow via the endip parameter in the SetPptpServerCfg function.
Affected Software
2 affected components
Tenda Ac6 Firmware=15.03.05.09
Tenda AC6
Event History
Mar 18, 2022
CVE Published
via MITRE·08:53 PM
Data Sourced
via MITRE·08:53 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-25460?
The severity of CVE-2022-25460 is critical with a CVSS score of 9.8.
2
What is the affected software for CVE-2022-25460?
The affected software for CVE-2022-25460 is Tenda Ac6 Firmware version 15.03.05.09.
3
How does CVE-2022-25460 affect Tenda AC6?
CVE-2022-25460 allows an attacker to cause a stack overflow via the endip parameter in the SetPptpServerCfg function of Tenda AC6 v15.03.05.09_multi firmware.
4
Is Tenda AC6 version 15.03.05.09 vulnerable to CVE-2022-25460?
Yes, Tenda AC6 version 15.03.05.09 is vulnerable to CVE-2022-25460.
5
How can I mitigate CVE-2022-25460?
To mitigate CVE-2022-25460, it is recommended to update to a patched version of Tenda Ac6 Firmware as soon as it becomes available.