CVE-2022-38565: Buffer Overflow
Published Aug 28, 2022
·Updated
Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formEmailTest. This vulnerability allows attackers to cause a Denial of Service (DoS) via the mailpwd parameter.
Affected Software
2 affected components
Tenda M3 Firmware=1.0.0.12\(4856\)
Tenda M3
Event History
Aug 28, 2022
CVE Published
via MITRE·04:48 PM
Data Sourced
via MITRE·04:48 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-38565?
CVE-2022-38565 is classified as a high severity vulnerability due to its potential to cause a Denial of Service.
2
How do I fix CVE-2022-38565?
To mitigate CVE-2022-38565, users should update the Tenda M3 firmware to the latest version provided by Tenda.
3
What types of attacks can CVE-2022-38565 enable?
CVE-2022-38565 can enable attackers to execute Denial of Service attacks through the exploitation of the heap buffer overflow.
4
On which device is CVE-2022-38565 found?
CVE-2022-38565 is found on the Tenda M3 router models running firmware version 1.0.0.12(4856).
5
What component of the Tenda M3 is affected by CVE-2022-38565?
CVE-2022-38565 affects the formEmailTest function within the Tenda M3's firmware.