Tenda · Tenda Ac18 · CVE-2022-38312
**Name of the Vulnerable Software and Affected Versions**
Tenda AC18 router versions 15.03.05.05 through 15.03.05.19
**Description**
A stack overflow issue was discovered in the Tenda AC18 router, specifically via the `list` parameter at the "/goform/SetIpMacBind" API endpoint.
**Recommendations**
For versions 15.03.05.05 through 15.03.05.19, consider restricting access to the "/goform/SetIpMacBind" API endpoint to minimize the risk of exploitation.
As a temporary workaround, avoid using the `list` parameter in the affected API endpoint until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.