CVE-2022-28556
Summary
| CVE | CVE-2022-28556 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-05-04 16:15:00 UTC |
| Updated | 2023-08-08 14:21:00 UTC |
| Description | Tenda AC15 US_AC15V1.0BR_V15.03.05.20_multi_TDE01.bin is vulnerable to Buffer Overflow. The stack overflow vulnerability lies in the /goform/setpptpservercfg interface of the web. The sent post data startip and endip are copied to the stack using the sanf function, resulting in stack overflow. Similarly, this vulnerability can be used together with CVE-2021-44971 |
Risk And Classification
Problem Types: CWE-787
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Tenda | Ac15 | 1.0 | All | All | All |
| Operating System | Tenda | Ac15 Firmware | 15.03.05.20_multi_tde01 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| TendaAC15_vul/TendaAC15-vul.md at main · doudoudedi/TendaAC15_vul · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.