CVE-2022-28970: High severity tenda ax1806 firmware vulnerability
Published May 6, 2022
·Updated
Tenda AX1806 v1.0.0.1 was discovered to contain a heap overflow via the mac parameter in the function GetParentControlInfo. This vulnerability allows attackers to cause a Denial of Service (DoS).
Affected Software
2 affected components
Tenda Ax1806 Firmware=1.0.0.1
Tenda AX1806
Event History
May 6, 2022
CVE Published
via MITRE·01:08 PM
Data Sourced
via MITRE·01:08 PM
Description
Frequently Asked Questions
1
What is CVE-2022-28970?
CVE-2022-28970 is a vulnerability found in Tenda AX1806 v1.0.0.1 firmware that allows attackers to cause a Denial of Service (DoS) through a heap overflow.
2
What software versions are affected by CVE-2022-28970?
Tenda AX1806 v1.0.0.1 firmware is affected by CVE-2022-28970.
3
How severe is CVE-2022-28970?
CVE-2022-28970 has a severity rating of 7.5 (high).
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2022-28970?
The CWE ID for CVE-2022-28970 is CWE-787.
5
How can I mitigate the CVE-2022-28970 vulnerability?
To mitigate the CVE-2022-28970 vulnerability, it is recommended to update to a patched version of Tenda AX1806 firmware when available.