A vulnerability was found in Tenda CH22 1.0.0.1. This affects the function fromAdvSetWan of the file /goform/AdvSetWan of the component Parameter Handler. The manipulation of the argument wanmode results in stack-based buffer overflow.
The attack can be executed remotely. The exploit has been made public and could be used.
Attack Parameters
Impact Assessment
CVSS Vector v4.0
Weakness Type (CWE)
Vulnerable Products 2
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Tenda Ch22_Firmware
cpe:2.3:o:tenda:ch22_firmware:1.0.0.1:*:*:*:*:*:*:*
|
— | — |
|
Tenda Ch22
cpe:2.3:h:tenda:ch22:-:*:*:*:*:*:*:*
|
— | — |