A Buffer Overflow vulnerability exists in Tenda Router AX12 V22.03.01.21_CN in the sub_422CE4 function in page /goform/setIPv6Status via the prefixDelegate parameter, which causes a Denial of Service.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.tenda.com.cn/ | vendor advisory |
http://tendawifi.com/index.html | broken link |
https://www.tenda.com.cn/product/AX12.html | product vendor advisory |
https://github.com/sec-bin/IoT-CVE/tree/main/Tenda/AX12/2 | third party advisory exploit |