Vulnerability Description
The Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576) is affected by a password exposure vulnerability. When combined with the improper authorization/improper session management vulnerability, an attacker with access to the router may be able to expose sensitive information which they're not explicitly authorized to have.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tenda | W15E Firmware | 15.11.0.10\(1576\) |
| Tenda | W15E | 2.0 |
Related Weaknesses (CWE)
References
- https://boschko.ca/tenda_ac1200_router/ExploitTechnical DescriptionThird Party Advisory
- https://boschko.ca/tenda_ac1200_router/ExploitTechnical DescriptionThird Party Advisory
FAQ
What is CVE-2022-40845?
CVE-2022-40845 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576) is affected by a password exposure vulnerability. When combined with the improper authorization/improper session management vulnerability, an att...
How severe is CVE-2022-40845?
CVE-2022-40845 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-40845?
Check the references section above for vendor advisories and patch information. Affected products include: Tenda W15E Firmware, Tenda W15E.