First published: Tue May 03 2022(Updated: )
There is a stack overflow vulnerability in the goform/fast_setting_wifi_set function in the httpd service of Tenda ac9 15.03.2.21_cn router. An attacker can obtain a stable shell through a carefully constructed payload
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tenda Ac9 Firmware | =15.03.2.21_cn | |
Tenda AC9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-28560.
The severity of CVE-2022-28560 is critical with a score of 9.8.
Tenda ac9 15.03.2.21_cn router with firmware version 15.03.2.21_cn is affected by CVE-2022-28560.
An attacker can exploit CVE-2022-28560 by carefully constructing a payload that triggers a stack overflow vulnerability in the goform/fast_setting_wifi_set function of the httpd service, allowing them to obtain a stable shell.
No, Tenda AC9 is not vulnerable to CVE-2022-28560.