CVE-2022-28561: Critical severity tenda ax12 firmware vulnerability
There is a stack overflow vulnerability in the /goform/setMacFilterCfg function in the httpd service of Tenda ax12 22.03.01.21cn router. An attacker can obtain a stable shell through a carefully constructed payload
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-28561?
CVE-2022-28561 is a stack overflow vulnerability in the /goform/setMacFilterCfg function in the httpd service of Tenda AX12 22.03.01.21_cn router.
How can an attacker exploit CVE-2022-28561?
An attacker can exploit CVE-2022-28561 by sending a carefully constructed payload to the vulnerable /goform/setMacFilterCfg function, allowing them to obtain a stable shell.
What is the severity of CVE-2022-28561?
CVE-2022-28561 has a severity rating of 9.8 (Critical).
What software versions are affected by CVE-2022-28561?
The Tenda AX12 firmware version 22.03.01.21_cn is affected by CVE-2022-28561.
How can I fix CVE-2022-28561?
To fix CVE-2022-28561, it is recommended to update the Tenda AX12 router firmware to a patched version provided by the vendor.