A vulnerability was determined in Tenda CH22 1.0.0.1. Affected is the function formWebTypeLibrary of the file /goform/webtypelibrary of the component Parameter Handler. This manipulation of the argument webSiteId causes stack-based buffer overflow.
The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Attack Parameters
Impact Assessment
CVSS Vector v4.0
Weakness Type (CWE)
Vulnerable Products 2
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Tenda Ch22_Firmware
cpe:2.3:o:tenda:ch22_firmware:1.0.0.1:*:*:*:*:*:*:*
|
— | — |
|
Tenda Ch22
cpe:2.3:h:tenda:ch22:-:*:*:*:*:*:*:*
|
— | — |