CVE-2022-46586: Critical severity trendnet tew-755ap vulnerability
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the qcawifi.wifi%dvap%d.maclist parameter in the kickbanwifimacallow (sub415B00) function.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-46586?
CVE-2022-46586 is a vulnerability found in TRENDnet TEW755AP version 1.13B01, which allows an attacker to trigger a stack overflow via the qcawifi.wifi%d_vap%d.maclist parameter in the kick_ban_wifi_mac_allow function.
How severe is CVE-2022-46586?
CVE-2022-46586 has a severity rating of 9.8, which is considered critical.
What software versions are affected by CVE-2022-46586?
TRENDnet TEW755AP version 1.13B01 is affected by CVE-2022-46586.
How can an attacker exploit CVE-2022-46586?
An attacker can exploit CVE-2022-46586 by sending malicious input to the qcawifi.wifi%d_vap%d.maclist parameter in the kick_ban_wifi_mac_allow function, triggering a stack overflow and potentially executing arbitrary code.
Is there a fix for CVE-2022-46586?
Currently, there is no known fix for CVE-2022-46586. It is recommended to apply any patches or updates provided by the vendor or follow their recommended mitigation steps.