PT-2022-7318 · Tenda · Tenda M3

Published

2022-07-01

·

Updated

2023-08-08

·

CVE-2022-32043

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Tenda M3 version 1.0.0.12
Description The issue is related to a stack overflow in the formSetAccessCodeInfo function, which can be exploited to cause a denial of service. This can be achieved by a remote attacker. The vulnerable function is also accessible via the goform/setAccessCodeData endpoint.
Recommendations For Tenda M3 version 1.0.0.12, consider disabling the formSetAccessCodeInfo function until a patch is available. Restrict access to the goform/setAccessCodeData endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Stack Overflow

Weakness Enumeration

Related Identifiers

BDU:2024-03349
CVE-2022-32043

Affected Products

Tenda M3