CVE-2022-45648: Buffer Overflow
Published Dec 2, 2022
·Updated
Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the devName parameter in the formSetDeviceName function.
Affected Software
4 affected components
Tendacn Ac6 Firmware=15.03.05.19
Tendacn Ac6=1.0
All of the following
Tendacn Ac6 Firmware=15.03.05.19
Tendacn Ac6=1.0
Event History
Dec 2, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-45648?
CVE-2022-45648 is a vulnerability found in Tenda AC6V1.0 V15.03.05.19 firmware that allows a buffer overflow via the devName parameter in the formSetDeviceName function.
2
How severe is CVE-2022-45648?
CVE-2022-45648 has a severity rating of 7.5 (high).
3
Which software version is affected by CVE-2022-45648?
The Tenda AC6V1.0 firmware version 15.03.05.19 is affected by CVE-2022-45648.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2022-45648?
CVE-2022-45648 is associated with CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) and CWE-120 (Buffer Copy without Checking Size of Input).
5
Is Tenda AC6V1.0 hardware version 1.0 vulnerable to CVE-2022-45648?
No, Tenda AC6V1.0 hardware version 1.0 is not vulnerable to CVE-2022-45648.