CVE-2022-40868: Critical severity Tenda W20e Firmware vulnerability
Published Sep 23, 2022
·Updated
Tenda W20E router V15.11.0.6 (USW20EV4.0brV15.11.0.6(10681546841)CNTDC) contains a stack overflow vulnerability in the function formDelDhcpRule with the request /goform/delDhcpRules/
Affected Software
4 affected components
Tenda W20e Firmware=15.11.0.6
Tenda W20E
All of the following
Tenda W20e Firmware=15.11.0.6
Tenda W20E
Event History
Sep 23, 2022
CVE Published
via MITRE·02:22 PM
Data Sourced
via MITRE·02:22 PM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-40868?
CVE-2022-40868 is classified as a high severity vulnerability due to the potential for remote exploitation.
2
How do I fix CVE-2022-40868?
To mitigate CVE-2022-40868, update the Tenda W20E router firmware to the latest version that addresses this vulnerability.
3
What impact does CVE-2022-40868 have on the Tenda W20E router?
CVE-2022-40868 allows an attacker to exploit a stack overflow, potentially leading to unauthorized access or system instability.
4
Which firmware versions are affected by CVE-2022-40868?
CVE-2022-40868 affects Tenda W20E routers running firmware version 15.11.0.6.
5
Is it safe to use the Tenda W20E router with the CVE-2022-40868 vulnerability present?
Using the Tenda W20E router with CVE-2022-40868 unaddressed poses security risks and is not recommended.