PT-2022-27559 · Tenda · Tenda W30E

CVE-2022-45517

·

Published

2022-12-08

·

Updated

2022-12-09

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Tenda W30E version 1.0.1.25(633)
Description A stack overflow issue was discovered via the page parameter at the "/goform/VirtualSer" API endpoint.
Recommendations For Tenda W30E version 1.0.1.25(633), consider disabling access to the "/goform/VirtualSer" API endpoint until a patch is available. Avoid using the page parameter in this endpoint to minimize the risk of exploitation.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-45517

Affected Products

Tenda W30E