CVE-2022-40867: Critical severity Tenda W20e Firmware vulnerability
Tenda W20E router V15.11.0.6 (USW20EV4.0brV15.11.0.6(10681546841)CNTDC) contains a stack overflow vulnerability in the function formIPMacBindDel with the request /goform/delIpMacBind/
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-40867?
CVE-2022-40867 has been classified as a high severity vulnerability due to the potential for remote exploitation leading to denial of service.
How do I fix CVE-2022-40867?
To fix CVE-2022-40867, you should update the Tenda W20E router to the latest firmware version that addresses this vulnerability.
What is the impact of CVE-2022-40867?
The impact of CVE-2022-40867 includes the potential for unauthorized access and the possibility to crash the router due to stack overflow.
Which versions of Tenda W20E are affected by CVE-2022-40867?
Tenda W20E running firmware version 15.11.0.6 is affected by CVE-2022-40867.
How does CVE-2022-40867 operate?
CVE-2022-40867 operates by exploiting a stack overflow in the formIPMacBindDel function during a specific request to the router.