PT-2023-15587 · Tenda · Tenda W20E

Published

2022-12-25

·

Updated

2025-03-26

·

CVE-2022-48130

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Tenda W20E version 15.11.0.6
Description The issue concerns multiple stack overflows in the function formSetStaticRoute, which can be triggered via the parameters staticRouteNet, staticRouteMask, staticRouteGateway, and staticRouteWAN.
Recommendations For Tenda W20E version 15.11.0.6, consider disabling the formSetStaticRoute function until a patch is available to prevent potential exploitation. Restrict access to the parameters staticRouteNet, staticRouteMask, staticRouteGateway, and staticRouteWAN to minimize the risk of stack overflows. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-04718
CVE-2022-48130

Affected Products

Tenda W20E