First published: Wed Oct 19 2022(Updated: )
Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the timeZone parameter at /goform/SetSysTimeCfg.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tenda TX3 Firmware | =16.03.13.11 | |
Tenda Tx3 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-43028 has been categorized as a high severity vulnerability due to the potential for remote code execution through stack overflow.
To fix CVE-2022-43028, update the Tenda TX3 firmware to the latest version that addresses this vulnerability.
The vulnerable parameter in CVE-2022-43028 is the timeZone parameter within the /goform/SetSysTimeCfg endpoint.
CVE-2022-43028 specifically affects Tenda TX3 devices running firmware version 16.03.13.11.
Yes, CVE-2022-43028 can be exploited remotely if the attacker has access to the affected endpoint.