First published: Wed May 11 2022(Updated: )
Tenda AX1803 v1.0.0.1_2890 is vulnerable to Buffer Overflow. The vulnerability lies in rootfs_ In / goform / setsystimecfg of / bin / tdhttpd in ubif file system, attackers can access http://ip/goform/SetSysTimeCfg, and by setting the ntpserve parameter, the stack buffer overflow can be caused to achieve the effect of router denial of service.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tenda Ax1803 Firmware | =1.0.0.1_2890 | |
Tenda AX1803 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-30040 is a vulnerability in Tenda AX1803 v1.0.0.1_2890 that allows for a buffer overflow attack.
CVE-2022-30040 has a severity rating of 7.5 (high).
Tenda AX1803 Firmware version 1.0.0.1_2890 is affected by CVE-2022-30040.
An attacker can exploit CVE-2022-30040 by accessing the http://ip/goform/SetSysTimeCfg URL and causing a stack buffer overflow by setting the ntpserve parameter.
Yes, you can find more information about CVE-2022-30040 at the following links: [GitHub - CVE-2022-30040](https://github.com/Le1a/CVE-2022-30040) and [GitHub - Tenda AX1803 Denial-of-service](https://github.com/Le1a/Tenda-AX1803-Denial-of-service).