PT-2022-25575 · Tenda · Tenda Ac1200 Router

Olivier Laflamme

·

Published

2022-11-15

·

Updated

2023-01-27

·

CVE-2022-40844

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Tenda AC1200 Router model W15Ev2 version V15.11.0.10(1576)
Description A Stored Cross Site Scripting (XSS) issue exists, allowing an attacker to execute JavaScript code via the application's website filtering tab, specifically the URL body.
Recommendations For Tenda AC1200 Router model W15Ev2 version V15.11.0.10(1576), as a temporary workaround, consider restricting access to the website filtering tab until a patch is available. Avoid using the URL body in the affected tab to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-40844

Affected Products

Tenda Ac1200 Router