Security readout for executives and security teams
Plain-English summary
CVE-2022-45671 is a high-severity buffer overflow reported in Tenda i22 firmware V1.0.0.3(4687). A remote unauthenticated request to the affected app filter rule handling can cause an availability impact. For executives, the main concern is service disruption on exposed wireless infrastructure, not confirmed data theft or active exploitation.
Executive priority
Prioritize remediation for any internet-facing or business-critical Tenda i22 deployments. The issue is high severity for availability, but the provided sources do not show confirmed exploitation or a named patch, so urgency should be driven by exposure and operational importance.
Technical view
The CVE describes CWE-120 buffer overflow handling of the appData parameter in formSetAppFilterRule on Tenda i22 V1.0.0.3(4687). CVSS 3.1 is 7.5 with AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, indicating network-reachable, unauthenticated availability impact. Sources do not identify a fixed version.
Likely exposure
Exposure is likely limited to Tenda i22 devices running firmware V1.0.0.3(4687), especially where the management interface is reachable from untrusted networks. The CVE record’s normalized affected-product fields are incomplete, so asset validation should rely on device model and firmware evidence.
Exploitation context
The CVE is not listed as CISA KEV in the provided bundle, and no cited source confirms active exploitation. A public GitHub write-up is referenced, so vulnerability details are public, but exploitation status remains unconfirmed from the provided evidence.
Researcher notes
Evidence is sparse. The CVE record names the vulnerable function and parameter, CVSS vector, and one GitHub reference, but affected CPE/vendor fields are n/a and no fixed release is cited. Avoid broad product claims beyond Tenda i22 V1.0.0.3(4687).
Mitigation direction
- Identify Tenda i22 devices and confirm firmware versions.
- Check Tenda or device supplier guidance for fixed firmware.
- Apply vendor-provided firmware if available.
- Restrict management access to trusted admin networks or VPN.
- Block internet exposure for affected device administration interfaces.
- Monitor affected devices for crashes, restarts, or service instability.
Validation and detection
- Inventory network devices for Tenda i22 model identifiers.
- Record firmware version and compare against V1.0.0.3(4687).
- Confirm admin interfaces are not reachable from the internet.
- Review firewall rules limiting access to management services.
- Check monitoring for unexplained device reboots or outages.
- Track vendor advisories because sources do not name a fix.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CWE-120: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Open ATT&CK lookupCVE-2022-45671 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- High
- CVSS
- 7.5 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H3.93.6Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
7.5HighVector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source materials
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.
