PT-2022-12491 · Tenda · Tenda Routers G3+1

Published

2022-02-04

·

Updated

2022-02-08

·

CVE-2021-45992

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Tenda routers G1 and G3 version 15.11.0.17(9502) CN
Description A stack overflow was discovered in the function formSetQvlanList, allowing attackers to cause a Denial of Service (DoS) via the qvlanName parameter.
Recommendations For version 15.11.0.17(9502) CN, as a temporary workaround, consider restricting access to the formSetQvlanList function until a patch is available. Avoid using the qvlanName parameter in the affected API endpoint until the issue is resolved.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-45992

Affected Products

Tenda Routers G1
Tenda Routers G3