CVE-2022-27022: Critical severity tenda ac9 vulnerability
Published Apr 7, 2022
·Updated
There is a stack overflow vulnerability in the SetSysTimeCfg() function in the httpd service of Tenda AC9 V15.03.2.21cn. The attacker can obtain a stable root shell through a constructed payload.
Affected Software
2 affected components
Tenda Ac9 Firmware=15.03.2.21_cn
Tenda Ac9
Event History
Apr 7, 2022
CVE Published
via MITRE·03:02 PM
Data Sourced
via MITRE·03:02 PM
Description
Frequently Asked Questions
1
What is CVE-2022-27022?
CVE-2022-27022 is a stack overflow vulnerability in the SetSysTimeCfg() function in the httpd service of Tenda AC9 V15.03.2.21_cn.
2
How can an attacker exploit CVE-2022-27022?
An attacker can exploit CVE-2022-27022 by constructing a payload to obtain a stable root shell.
3
What is the severity of CVE-2022-27022?
The severity of CVE-2022-27022 is critical with a CVSS score of 9.8.
4
Which software version is affected by CVE-2022-27022?
Tenda AC9 V15.03.2.21_cn firmware is affected by CVE-2022-27022.
5
Is Tenda AC9 vulnerable to CVE-2022-27022?
No, Tenda AC9 is not vulnerable to CVE-2022-27022.