CVE-2022-37292: Buffer Overflow
Published Aug 25, 2022
·Updated
Tenda AX12 V22.03.01.21CN is vulnerable to Buffer Overflow. This overflow is triggered in the sub42FDE4 function, which satisfies the request of the upper-level interface function sub430124, that is, handles the post request under /goform/SetIpMacBind.
Affected Software
2 affected components
Tenda Ax12 Firmware=22.03.01.21_cn
Tenda AX12
Event History
Aug 25, 2022
CVE Published
via MITRE·03:07 PM
Data Sourced
via MITRE·03:07 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Tenda AX12 firmware vulnerability?
The vulnerability ID for this Tenda AX12 firmware vulnerability is CVE-2022-37292.
2
What is the severity of CVE-2022-37292?
The severity of CVE-2022-37292 is medium with a severity value of 5.5.
3
Which software versions are affected by CVE-2022-37292?
The Tenda AX12 firmware version 22.03.01.21_CN is affected by CVE-2022-37292.
4
How is the Buffer Overflow vulnerability triggered in Tenda AX12 firmware?
The Buffer Overflow vulnerability in Tenda AX12 firmware is triggered in the sub_42FDE4 function, which handles the post request under /goform/SetIpMacBind.
5
Is Tenda AX12 hardware vulnerable to CVE-2022-37292?
No, the Tenda AX12 hardware itself is not vulnerable to CVE-2022-37292.