First published: Thu Dec 08 2022(Updated: )
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the cmdinput parameter at /goform/exeCommand.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tenda W30e Firmware | =1.0.1.25\(633\) | |
Tenda W30e Firmware | ||
All of | ||
=1.0.1.25\(633\) | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-45505 has not been specifically rated by CVSS but represents a stack overflow vulnerability which is generally considered to have a high severity level.
To fix CVE-2022-45505, upgrade the Tenda W30E firmware to a version that is not affected by this vulnerability.
CVE-2022-45505 specifically affects the Tenda W30E Firmware version 1.0.1.25(633).
The impact of CVE-2022-45505 could allow an attacker to execute arbitrary code on the affected device due to the stack overflow.
Yes, CVE-2022-45505 can potentially be exploited remotely through the vulnerable cmdinput parameter.