CVE-2022-28556

HIGH

Tenda AC15 - Buffer Overflow in setpptpservercfg

Title source: llm
STIX 2.1

Description

Tenda AC15 US_AC15V1.0BR_V15.03.05.20_multi_TDE01.bin is vulnerable to Buffer Overflow. The stack overflow vulnerability lies in the /goform/setpptpservercfg interface of the web. The sent post data startip and endip are copied to the stack using the sanf function, resulting in stack overflow. Similarly, this vulnerability can be used together with CVE-2021-44971

References (1)

Core 1

Scores

CVSS v3 7.5
EPSS 0.0035
EPSS Percentile 57.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-787
Status published
Products (1)
tenda/ac15_firmware 15.03.05.20_multi_tde01
Published May 04, 2022
Tracked Since Feb 18, 2026