PT-2022-19077 · Tenda · Tenda Ac15

Published

2022-05-04

·

Updated

2023-08-08

·

CVE-2022-28556

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Tenda AC15 version 15.03.05.20
Description The issue is related to a buffer overflow in the web interface, specifically in the "/goform/setpptpservercfg" API endpoint. The vulnerability arises from the handling of POST data, where the startip and endip variables are copied to the stack using the sanf function, leading to a stack overflow.
Recommendations For version 15.03.05.20, as a temporary workaround, consider restricting access to the "/goform/setpptpservercfg" API endpoint until a patch is available. Avoid using the startip and endip variables in this endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2022-28556

Affected Products

Tenda Ac15