Vulnerability Description
Tenda M3 V1.0.0.12 was discovered to contain multiple stack overflow vulnerabilities via the ssidList, storeName, and trademark parameters in the function formSetStoreWeb.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tenda | M3 Firmware | 1.0.0.12 |
| Tenda | M3 | - |
Related Weaknesses (CWE)
References
- https://github.com/d1tto/IoT-vuln/tree/main/Tenda/M3/formSetStoreWebExploitThird Party Advisory
- https://github.com/d1tto/IoT-vuln/tree/main/Tenda/M3/formSetStoreWebExploitThird Party Advisory
FAQ
What is CVE-2022-32036?
CVE-2022-32036 is a vulnerability with a CVSS score of 7.5 (HIGH). Tenda M3 V1.0.0.12 was discovered to contain multiple stack overflow vulnerabilities via the ssidList, storeName, and trademark parameters in the function formSetStoreWeb.
How severe is CVE-2022-32036?
CVE-2022-32036 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-32036?
Check the references section above for vendor advisories and patch information. Affected products include: Tenda M3 Firmware, Tenda M3.