CVE-2021-45392
high · 7.5A Buffer Overflow vulnerability exists in Tenda Router AX12 V22.03.01.21_CN in the sub_422CE4 function in page /goform/setIPv6Status via the prefixDelegate parameter, which causes a Denial of Service.
7.5
CVSS
12.3%
EPSS (exploit prob.)
96th
EPSS percentile
2022-02-14
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses
CWE-787
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| tenda | ax12_firmware | 22.03.01.21_cn |
| tenda | ax12 | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://tendawifi.com/index.html
- https://github.com/sec-bin/IoT-CVE/tree/main/Tenda/AX12/2
- https://www.tenda.com.cn/
- https://www.tenda.com.cn/product/AX12.html
- http://tendawifi.com/index.html
- https://github.com/sec-bin/IoT-CVE/tree/main/Tenda/AX12/2
- https://www.tenda.com.cn/
- https://www.tenda.com.cn/product/AX12.html
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2021-45392