ID

VAR-202203-1022


CVE

CVE-2022-25548


TITLE

Tenda AX1806 stack overflow vulnerability

Trust: 0.6

sources: CNVD: CNVD-2022-22748

DESCRIPTION

Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability allows attackers to cause a Denial of Service (DoS) via the serverName parameter. Tenda AX1806 is a WiFi6 wireless router from Tenda, China. A stack overflow vulnerability exists in Tenda AX1806, which allows remote attackers to use the vulnerability to submit special requests that can crash the application or execute arbitrary code in the context of the application

Trust: 1.44

sources: NVD: CVE-2022-25548 // CNVD: CNVD-2022-22748

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2022-22748

AFFECTED PRODUCTS

vendor:tendamodel:ax1806scope:eqversion:1.0.0.1

Trust: 1.0

vendor:tendamodel:ax1806scope:eqversion:v1.0.0.1

Trust: 0.6

sources: CNVD: CNVD-2022-22748 // NVD: CVE-2022-25548

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2022-25548
value: HIGH

Trust: 1.0

CNVD: CNVD-2022-22748
value: HIGH

Trust: 0.6

CNNVD: CNNVD-202203-881
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2022-25548
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

CNVD: CNVD-2022-22748
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2022-25548
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.1

Trust: 1.0

sources: CNVD: CNVD-2022-22748 // CNNVD: CNNVD-202203-881 // NVD: CVE-2022-25548

PROBLEMTYPE DATA

problemtype:CWE-787

Trust: 1.0

sources: NVD: CVE-2022-25548

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202203-881

TYPE

buffer error

Trust: 0.6

sources: CNNVD: CNNVD-202203-881

PATCH

title:Patch for Tenda AX1806 stack overflow vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/327881

Trust: 0.6

sources: CNVD: CNVD-2022-22748

EXTERNAL IDS

db:NVDid:CVE-2022-25548

Trust: 2.2

db:CNVDid:CNVD-2022-22748

Trust: 0.6

db:CNNVDid:CNNVD-202203-881

Trust: 0.6

sources: CNVD: CNVD-2022-22748 // CNNVD: CNNVD-202203-881 // NVD: CVE-2022-25548

REFERENCES

url:https://github.com/sec-bin/iot-cve/tree/main/tenda/ax1806/5

Trust: 1.6

url:https://nvd.nist.gov/vuln/detail/cve-2022-25548

Trust: 0.6

url:https://cxsecurity.com/cveshow/cve-2022-25548/

Trust: 0.6

sources: CNVD: CNVD-2022-22748 // CNNVD: CNNVD-202203-881 // NVD: CVE-2022-25548

SOURCES

db:CNVDid:CNVD-2022-22748
db:CNNVDid:CNNVD-202203-881
db:NVDid:CVE-2022-25548

LAST UPDATE DATE

2024-11-23T22:15:51.158000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2022-22748date:2022-03-25T00:00:00
db:CNNVDid:CNNVD-202203-881date:2022-03-14T00:00:00
db:NVDid:CVE-2022-25548date:2024-11-21T06:52:20.160

SOURCES RELEASE DATE

db:CNVDid:CNVD-2022-22748date:2022-03-25T00:00:00
db:CNNVDid:CNNVD-202203-881date:2022-03-10T00:00:00
db:NVDid:CVE-2022-25548date:2022-03-10T17:47:09.767