CVE-2022-25558: High severity tenda ax1806 firmware vulnerability
Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function formSetProvince. This vulnerability allows attackers to cause a Denial of Service (DoS) via the ProvinceCode parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-25558?
CVE-2022-25558 is a vulnerability in Tenda AX1806 v1.0.0.1 that allows attackers to cause a Denial of Service (DoS) via the ProvinceCode parameter.
What is the severity of CVE-2022-25558?
The severity of CVE-2022-25558 is high with a CVSS score of 7.5.
How can attackers exploit CVE-2022-25558?
Attackers can exploit CVE-2022-25558 by sending a specially crafted ProvinceCode parameter, causing a stack overflow and resulting in a Denial of Service (DoS).
Is Tenda AX1806 firmware version 1.0.0.1 affected by CVE-2022-25558?
Yes, Tenda AX1806 firmware version 1.0.0.1 is affected by CVE-2022-25558.
How can I mitigate the vulnerability in Tenda AX1806 v1.0.0.1?
To mitigate the vulnerability in Tenda AX1806 v1.0.0.1, it is recommended to update to a patched version of the firmware provided by the vendor.