CVE-2022-45980: CSRF
Published Dec 12, 2022
·Updated
Tenda AX12 V22.03.01.21CN was discovered to contain a Cross-Site Request Forgery (CSRF) via /goform/SysToolRestoreSet .
Affected Software
4 affected components
Tenda Ax12 Firmware=22.03.01.21_cn
Tenda AX12
All of the following
Tenda Ax12 Firmware=22.03.01.21_cn
Tenda AX12
Event History
Dec 12, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-45980?
CVE-2022-45980 is a vulnerability discovered in the Tenda AX12 V22.03.01.21_CN firmware, which allows for Cross-Site Request Forgery (CSRF) attacks through the /goform/SysToolRestoreSet endpoint.
2
What is the severity of CVE-2022-45980?
CVE-2022-45980 has a severity rating of 8.8 (high).
3
How does CVE-2022-45980 affect Tenda AX12 devices?
CVE-2022-45980 affects Tenda AX12 devices running the V22.03.01.21_CN firmware, allowing attackers to perform Cross-Site Request Forgery (CSRF) attacks.
4
Is Tenda AX12 firmware version 22.03.01.21_CN vulnerable to CVE-2022-45980?
Yes, the Tenda AX12 firmware version 22.03.01.21_CN is vulnerable to CVE-2022-45980.
5
How can I protect my Tenda AX12 device from CVE-2022-45980?
To protect your Tenda AX12 device from CVE-2022-45980, it is recommended to update to a patched firmware version as soon as it becomes available.