← back
CVE-2022-45980highCWE-352

CVE-2022-45980

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.8epss 7.5%
exploitation probability
7.5%top 6% of all CVEs
observed exploitation
nono source reports it
In short

The Tenda AX12 router has a flaw that allows attackers to trick users into performing unwanted actions on their router settings through malicious websites. An attacker can force a user to restore the router to default settings without their knowledge.

Technical detail

A Cross-Site Request Forgery (CSRF) vulnerability exists in the /goform/SysToolRestoreSet endpoint of Tenda AX12 V22.03.01.21_CN. The vulnerability permits an unauthenticated attacker to forge requests that execute system restore operations by tricking an authenticated router administrator into visiting a malicious website, resulting in potential loss of router configuration and security posture.

Summary generated and translated by AI from the official description.
Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via /goform/SysToolRestoreSet .
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
n/a · n/a