PT-2022-21064 · Tenda · Tenda M3

Published

2022-07-01

·

Updated

2023-08-08

·

CVE-2022-32037

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Tenda M3 version 1.0.0.12
Description A stack overflow issue was discovered via the function formSetAPCfg(). This issue may allow for exploitation, potentially leading to unauthorized access or control. No information is available regarding the estimated number of potentially affected devices or real-world incidents where this issue was exploited.
Recommendations For Tenda M3 version 1.0.0.12, consider disabling the formSetAPCfg() function as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2022-32037

Affected Products

Tenda M3