First published: Thu Apr 07 2022(Updated: )
There is a stack overflow vulnerability in the SetSysTimeCfg() function in the httpd service of Tenda AC9 V15.03.2.21_cn. The attacker can obtain a stable root shell through a constructed payload.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tenda Ac9 Firmware | =15.03.2.21_cn | |
Tenda AC9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-27022 is a stack overflow vulnerability in the SetSysTimeCfg() function in the httpd service of Tenda AC9 V15.03.2.21_cn.
An attacker can exploit CVE-2022-27022 by constructing a payload to obtain a stable root shell.
The severity of CVE-2022-27022 is critical with a CVSS score of 9.8.
Tenda AC9 V15.03.2.21_cn firmware is affected by CVE-2022-27022.
No, Tenda AC9 is not vulnerable to CVE-2022-27022.