CVE-2022-40876: Critical severity Tenda Ax1803 Firmware vulnerability
In Tenda ax1803 v1.0.0.1, the http requests handled by the fromAdvSetMacMtuWan functions, wanSpeed, cloneType, mac, can cause a stack overflow and enable remote code execution (RCE).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Tenda ax1803to a version that resolves this vulnerability.Fixed in v1.0.0.1 - Compensating control
Mitigate potential RCE by restricting inbound network access to the router so the vulnerable HTTP requests handled by fromAdvSetMacMtuWan (wanSpeed/cloneType/mac) cannot be reached remotely.
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-40876.
What is the severity of CVE-2022-40876?
The severity of CVE-2022-40876 is critical with a severity value of 9.8.
What is the affected software for CVE-2022-40876?
The affected software for CVE-2022-40876 is Tenda ax1803 v1.0.0.1 firmware.
How can CVE-2022-40876 be exploited?
CVE-2022-40876 can be exploited by sending HTTP requests to the vulnerable Tenda ax1803 v1.0.0.1 firmware.
Are there any fixes or patches available for CVE-2022-40876?
At the moment, there are no known fixes or patches available for CVE-2022-40876. It is recommended to update to a non-vulnerable version or use alternative security measures.