Vulnerability Description
A Buffer Overflow vulnerability exists in Tenda Router AX12 V22.03.01.21_CN in the sub_422CE4 function in the goform/setIPv6Status binary file /usr/sbin/httpd via the conType parameter, which causes a Denial of Service.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tenda | Ax12 Firmware | 22.03.01.21_cn |
| Tenda | Ax12 | - |
Related Weaknesses (CWE)
References
- http://tendawifi.com/index.htmlBroken Link
- https://github.com/sec-bin/IoT-CVE/tree/main/Tenda/AX12/1ExploitThird Party Advisory
- https://www.tenda.com.cn/Vendor Advisory
- https://www.tenda.com.cn/product/AX12.htmlProductVendor Advisory
- http://tendawifi.com/index.htmlBroken Link
- https://github.com/sec-bin/IoT-CVE/tree/main/Tenda/AX12/1ExploitThird Party Advisory
- https://www.tenda.com.cn/Vendor Advisory
- https://www.tenda.com.cn/product/AX12.htmlProductVendor Advisory
FAQ
What is CVE-2021-45391?
CVE-2021-45391 is a vulnerability with a CVSS score of 7.5 (HIGH). A Buffer Overflow vulnerability exists in Tenda Router AX12 V22.03.01.21_CN in the sub_422CE4 function in the goform/setIPv6Status binary file /usr/sbin/httpd via the conType parameter, which causes a...
How severe is CVE-2021-45391?
CVE-2021-45391 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-45391?
Check the references section above for vendor advisories and patch information. Affected products include: Tenda Ax12 Firmware, Tenda Ax12.