First published: Tue Nov 15 2022(Updated: )
In Tenda (Shenzhen Tenda Technology Co., Ltd) AC1200 Router model W15Ev2 V15.11.0.10(1576), a Stored Cross Site Scripting (XSS) issue exists allowing an attacker to execute JavaScript code via the applications website filtering tab, specifically the URL body.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tenda W15e Firmware | =15.11.0.10\(1576\) | |
Tenda AC1200 V-W15Ev2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-40844 is classified as a medium severity vulnerability due to its potential to allow stored cross-site scripting attacks.
To fix CVE-2022-40844, upgrade the Tenda AC1200 router firmware to a version that addresses the stored XSS vulnerability.
CVE-2022-40844 is a Stored Cross Site Scripting (XSS) vulnerability.
Users of the Tenda AC1200 Router model W15Ev2 running firmware version 15.11.0.10(1576) are affected by CVE-2022-40844.
Attackers can exploit CVE-2022-40844 to execute JavaScript code in the context of the affected application's website filtering functionality.