CVE-2022-45505: High severity tenda w30e firmware vulnerability
Published Dec 8, 2022
·Updated
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the cmdinput parameter at /goform/exeCommand.
Affected Software
4 affected components
Tenda W30e Firmware=1.0.1.25\(633\)
Tenda W30E
All of the following
Tenda W30e Firmware=1.0.1.25\(633\)
Tenda W30E
Event History
Dec 8, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-45505?
CVE-2022-45505 has not been specifically rated by CVSS but represents a stack overflow vulnerability which is generally considered to have a high severity level.
2
How do I fix CVE-2022-45505?
To fix CVE-2022-45505, upgrade the Tenda W30E firmware to a version that is not affected by this vulnerability.
3
What devices are affected by CVE-2022-45505?
CVE-2022-45505 specifically affects the Tenda W30E Firmware version 1.0.1.25(633).
4
What is the impact of CVE-2022-45505?
The impact of CVE-2022-45505 could allow an attacker to execute arbitrary code on the affected device due to the stack overflow.
5
Can CVE-2022-45505 be exploited remotely?
Yes, CVE-2022-45505 can potentially be exploited remotely through the vulnerable cmdinput parameter.