CVE-2022-45979: High severity tenda ax12 firmware vulnerability
Published Dec 12, 2022
·Updated
Tenda AX12 v22.03.01.21CN was discovered to contain a stack overflow via the ssid parameter at /goform/fastsettingwifiset .
Affected Software
4 affected components
Tenda Ax12 Firmware=22.03.01.21_cn
Tenda AX12
All of the following
Tenda Ax12 Firmware=22.03.01.21_cn
Tenda AX12
Event History
Dec 12, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-45979.
2
What is the severity of CVE-2022-45979?
The severity of CVE-2022-45979 is high with a CVSS score of 7.5.
3
How does CVE-2022-45979 impact Tenda AX12 v22.03.01.21_CN?
CVE-2022-45979 allows an attacker to trigger a stack overflow through the ssid parameter at /goform/fast_setting_wifi_set in Tenda AX12 v22.03.01.21_CN firmware.
4
Is Tenda AX12 v22.03.01.21_CN the only affected software?
No, Tenda AX12 v22.03.01.21_CN firmware is affected, while Tenda AX12 hardware itself is not vulnerable.
5
How can I mitigate the vulnerability in Tenda AX12 v22.03.01.21_CN?
To mitigate the vulnerability in Tenda AX12 v22.03.01.21_CN, it is recommended to update the firmware to a secure version provided by the vendor.