CVE-2022-37820: High severity tenda ax1803 firmware vulnerability
Published Aug 25, 2022
·Updated
Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the ddnsEn parameter in the function formSetSysToolDDNS.
Affected Software
2 affected components
Tenda Ax1803 Firmware=1.0.0.1
Tenda ax1803
Event History
Aug 25, 2022
CVE Published
via MITRE·02:07 PM
Data Sourced
via MITRE·02:07 PM
Description
Frequently Asked Questions
1
What is CVE-2022-37820?
CVE-2022-37820 is a vulnerability found in Tenda AX1803 v1.0.0.1 firmware that allows a stack overflow through the ddnsEn parameter in the function formSetSysToolDDNS.
2
What is the severity of CVE-2022-37820?
The severity of CVE-2022-37820 is high with a CVSS score of 7.8.
3
How does CVE-2022-37820 affect Tenda AX1803 v1.0.0.1?
CVE-2022-37820 affects Tenda AX1803 v1.0.0.1 firmware by enabling a stack overflow when the ddnsEn parameter is used in the function formSetSysToolDDNS.
4
Is Tenda AX1803 v1.0.0.1 the only affected software?
No, Tenda AX1803 v1.0.0.1 firmware is the only affected software version, but the Tenda AX1803 device itself is not vulnerable.
5
How can I fix CVE-2022-37820 on my Tenda AX1803 v1.0.0.1?
To fix CVE-2022-37820 on Tenda AX1803 v1.0.0.1, update the firmware to a version that includes the security patch.