CVE-2020-22079
Severity CVSS v4.0:
Pending analysis
Type:
CWE-787
Out-of-bounds Write
Publication date:
29/10/2021
Last modified:
26/10/2022
Description
Stack-based buffer overflow in Tenda AC-10U AC1200 Router US_AC10UV1.0RTL_V15.03.06.48_multi_TDE01 allows remote attackers to execute arbitrary code via the timeZone parameter to goform/SetSysTimeCfg.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:tendacn:ac10u_firmware:15.03.06.48_multi_tde01:*:*:*:*:*:*:* | ||
| cpe:2.3:h:tendacn:ac10u:1.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tendacn:ac9_firmware:15.03.05.19\(6318\):*:*:*:*:*:*:* | ||
| cpe:2.3:h:tendacn:ac9:1.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tendacn:ac9_firmware:15.03.06.42_multi:*:*:*:*:*:*:* | ||
| cpe:2.3:h:tendacn:ac9:3.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



