CVE-2022-28560 is a critical stack overflow vulnerability affecting the Tenda AC9 15.03.2.21_cn router's httpd service, specifically within the goform/fast_setting_wifi_set function. With a CVSS score of 9.8, this vulnerability allows an unauthenticated attacker to achieve a stable shell on the device by sending a crafted payload over the network. While highly severe and easily exploitable with no user interaction required, there is currently no public exploit code available, nor is there evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
15.03.2.21_cnCPE matchmatch criteria | cpe:2.3:o:tenda:ac9_firmware:15.03.2.21_cn:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.