CVE-2022-28560: Critical severity tenda ac9 vulnerability
Published May 3, 2022
·Updated
There is a stack overflow vulnerability in the goform/fastsettingwifiset function in the httpd service of Tenda ac9 15.03.2.21cn router. An attacker can obtain a stable shell through a carefully constructed payload
Affected Software
2 affected components
Tenda Ac9 Firmware=15.03.2.21_cn
Tenda Ac9
Event History
May 3, 2022
CVE Published
via MITRE·03:20 PM
Data Sourced
via MITRE·03:20 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for the stack overflow vulnerability in the goform/fast_setting_wifi_set function in the httpd service of Tenda ac9 15.03.2.21_cn router?
The vulnerability ID is CVE-2022-28560.
2
What is the severity of CVE-2022-28560?
The severity of CVE-2022-28560 is critical with a score of 9.8.
3
Which software is affected by CVE-2022-28560?
Tenda ac9 15.03.2.21_cn router with firmware version 15.03.2.21_cn is affected by CVE-2022-28560.
4
How can an attacker exploit CVE-2022-28560?
An attacker can exploit CVE-2022-28560 by carefully constructing a payload that triggers a stack overflow vulnerability in the goform/fast_setting_wifi_set function of the httpd service, allowing them to obtain a stable shell.
5
Is Tenda AC9 vulnerable to CVE-2022-28560?
No, Tenda AC9 is not vulnerable to CVE-2022-28560.