First published: Tue May 03 2022(Updated: )
There is a stack overflow vulnerability in the /goform/setMacFilterCfg function in the httpd service of Tenda ax12 22.03.01.21_cn router. An attacker can obtain a stable shell through a carefully constructed payload
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tenda Ax12 Firmware | =22.03.01.21_cn | |
Tenda AX12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-28561 is a stack overflow vulnerability in the /goform/setMacFilterCfg function in the httpd service of Tenda AX12 22.03.01.21_cn router.
An attacker can exploit CVE-2022-28561 by sending a carefully constructed payload to the vulnerable /goform/setMacFilterCfg function, allowing them to obtain a stable shell.
CVE-2022-28561 has a severity rating of 9.8 (Critical).
The Tenda AX12 firmware version 22.03.01.21_cn is affected by CVE-2022-28561.
To fix CVE-2022-28561, it is recommended to update the Tenda AX12 router firmware to a patched version provided by the vendor.