CVE-2022-27022

There is a stack overflow vulnerability in the SetSysTimeCfg() function in the httpd service of Tenda AC9 V15.03.2.21_cn. The attacker can obtain a stable root shell through a constructed payload.
References
Link Resource
https://github.com/EPhaha/IOT_vuln/tree/main/Tenda/AC9/14 Exploit Third Party Advisory
Configurations

Configuration 1


Information

Published : 2022-04-07 04:15

Updated : 2022-04-14 08:41


NVD link : CVE-2022-27022

Mitre link : CVE-2022-27022

Products Affected
No products.
CWE