PT-2022-27913 · Trendnet · Trendnet Tew755Ap

CVE-2022-46585

·

Published

2022-12-30

·

Updated

2023-01-05

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TRENDnet TEW755AP version 1.13B01
Description A stack overflow issue was discovered via the REMOTE USER parameter in the get access (sub 45AC2C) function.
Recommendations For TRENDnet TEW755AP version 1.13B01, consider restricting access to the get access (sub 45AC2C) function until a patch is available. Avoid using the REMOTE USER parameter in affected API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-46585

Affected Products

Trendnet Tew755Ap