PT-2022-25600 · Tenda · Tenda Ax1803

Riv4Ille

·

Published

2022-10-27

·

Updated

2025-05-07

·

CVE-2022-40876

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tenda ax1803 version 1.0.0.1
Description The issue concerns http requests handled by the fromAdvSetMacMtuWan functions, specifically the wanSpeed, cloneType, and mac variables, which can cause a stack overflow and enable remote code execution.
Recommendations For Tenda ax1803 version 1.0.0.1, consider disabling the fromAdvSetMacMtuWan function as a temporary workaround until a patch is available. Restrict access to the http requests that handle wanSpeed, cloneType, and mac variables to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2025-13116
CVE-2022-40876

Affected Products

Tenda Ax1803