PT-2022-27922 · Trendnet · Trendnet Tew755Ap

Published

2022-12-30

·

Updated

2023-01-05

·

CVE-2022-46594

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TRENDnet TEW755AP version 1.13B01
Description A stack overflow issue was discovered, related to the update file name parameter in the auto up fw (sub 420A04) function.
Recommendations For TRENDnet TEW755AP version 1.13B01, consider restricting access to the auto up fw function until a patch is available. Avoid using the update file name parameter in the affected function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2022-46594

Affected Products

Trendnet Tew755Ap