CVE-2022-28082: Critical severity tenda ax12 firmware vulnerability
Published May 4, 2022
·Updated
Tenda AX12 v22.03.01.21CN was discovered to contain a stack overflow via the list parameter at /goform/SetNetControlList.
Affected Software
2 affected components
Tenda Ax12 Firmware=22.03.01.21_cn
Tenda AX12
Event History
May 4, 2022
CVE Published
via MITRE·01:09 PM
Data Sourced
via MITRE·01:09 PM
Description
Frequently Asked Questions
1
What is CVE-2022-28082?
CVE-2022-28082 is a vulnerability found in Tenda AX12 firmware version 22.03.01.21_CN.
2
How severe is CVE-2022-28082?
CVE-2022-28082 has a severity rating of 9.8, which is considered critical.
3
How does CVE-2022-28082 affect Tenda AX12 devices?
CVE-2022-28082 affects Tenda AX12 devices running firmware version 22.03.01.21_CN.
4
What is the impact of CVE-2022-28082?
CVE-2022-28082 allows an attacker to perform a stack overflow via the 'list' parameter at /goform/SetNetControlList, potentially leading to remote code execution or denial of service.
5
Is there a fix available for CVE-2022-28082?
At the moment, there is no official fix available for CVE-2022-28082. It is recommended to update to a patched firmware version when it becomes available.