← Back to browse · API

CVE-2022-40855

Severity
CRITICAL
CVSS
9.8
EPSS
0.13495
Risk score
43.92
CISA KEV
No
PoC
No
Published
2022-09-23
Modified
2025-05-22
First seen
2026-08-07
Aliases
EUVD-2022-44112, GHSA-526F-868J-W52F
Products
n/a:n/a n/a
Sources
euvd EUVD-2022-44112

Description

Tenda W20E router V15.11.0.6 contains a stack overflow in the function formSetPortMapping with post request 'goform/setPortMapping/'. This vulnerability allows attackers to cause a Denial of Service (DoS) or Remote Code Execution (RCE) via the portMappingServer, portMappingProtocol, portMappingWan, porMappingtInternal, and portMappingExternal parameters.

References