In Tenda ax1803 v1.0.0.1, the http requests handled by the fromAdvSetMacMtuWan functions, wanSpeed, cloneType, mac, can cause a stack overflow and enable remote code execution (RCE).
                
            References
                    | Link | Resource | 
|---|---|
| https://www.cnblogs.com/L0g4n-blog/p/16695155.html | Exploit Third Party Advisory | 
| https://www.cnblogs.com/L0g4n-blog/p/16704071.html | Exploit Third Party Advisory | 
| https://www.cnblogs.com/L0g4n-blog/p/16695155.html | Exploit Third Party Advisory | 
| https://www.cnblogs.com/L0g4n-blog/p/16704071.html | Exploit Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
| AND | 
            
            
 
  | 
    
History
                    21 Nov 2024, 07:22
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://www.cnblogs.com/L0g4n-blog/p/16695155.html - Exploit, Third Party Advisory | |
| References | () https://www.cnblogs.com/L0g4n-blog/p/16704071.html - Exploit, Third Party Advisory | 
31 Oct 2022, 18:47
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:o:tenda:ax1803_firmware:1.0.0.1:*:*:*:*:*:*:* cpe:2.3:h:tenda:ax1803:-:*:*:*:*:*:*:*  | 
|
| References | (MISC) https://www.cnblogs.com/L0g4n-blog/p/16695155.html - Exploit, Third Party Advisory | |
| References | (MISC) https://www.cnblogs.com/L0g4n-blog/p/16704071.html - Exploit, Third Party Advisory | |
| CVSS | 
        v2 :  v3 :  | 
    
        v2 : unknown
         v3 : 9.8  | 
| CWE | CWE-787 | 
27 Oct 2022, 21:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2022-10-27 21:15
Updated : 2025-05-07 17:15
NVD link : CVE-2022-40876
Mitre link : CVE-2022-40876
CVE.ORG link : CVE-2022-40876
JSON object : View
Products Affected
                tenda
- ax1803_firmware
 - ax1803
 
CWE
                
                    
                        
                        CWE-787
                        
            Out-of-bounds Write
