7.8
CVE-2022-32036
- EPSS 0.31%
- Veröffentlicht 01.07.2022 18:15:09
- Zuletzt bearbeitet 21.11.2024 07:05:40
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Tenda M3 V1.0.0.12 was discovered to contain multiple stack overflow vulnerabilities via the ssidList, storeName, and trademark parameters in the function formSetStoreWeb.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tenda ≫ M3 Firmware Version1.0.0.12
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.31% | 0.541 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| nvd@nist.gov | 7.8 | 10 | 6.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:C
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.