Vulnerability Description
Tenda AC9 v15.03.2.21 was discovered to contain multiple stack overflows via the NPTR, V12, V10 and V11 parameter in the Formsetqosband function.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tenda | Ac9 Firmware | 15.03.2.21 |
| Tenda | Ac9 | - |
Related Weaknesses (CWE)
References
- https://github.com/EPhaha/IOT_vuln/tree/main/Tenda/AC9/4ExploitThird Party Advisory
- https://github.com/EPhaha/IOT_vuln/tree/main/Tenda/AC9/4ExploitThird Party Advisory
FAQ
What is CVE-2022-25431?
CVE-2022-25431 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Tenda AC9 v15.03.2.21 was discovered to contain multiple stack overflows via the NPTR, V12, V10 and V11 parameter in the Formsetqosband function.
How severe is CVE-2022-25431?
CVE-2022-25431 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-25431?
Check the references section above for vendor advisories and patch information. Affected products include: Tenda Ac9 Firmware, Tenda Ac9.