LiveActive security incident?Get immediate response
CVE Record

CVE-2022-45671: Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the appData parameter in the formS...

Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the appData parameter in the formSetAppFilterRule function.

HighCVSS 7.5Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

CVE-2022-45671 is a high-severity buffer overflow reported in Tenda i22 firmware V1.0.0.3(4687). A remote unauthenticated request to the affected app filter rule handling can cause an availability impact. For executives, the main concern is service disruption on exposed wireless infrastructure, not confirmed data theft or active exploitation.

Executive priority

Prioritize remediation for any internet-facing or business-critical Tenda i22 deployments. The issue is high severity for availability, but the provided sources do not show confirmed exploitation or a named patch, so urgency should be driven by exposure and operational importance.

Technical view

The CVE describes CWE-120 buffer overflow handling of the appData parameter in formSetAppFilterRule on Tenda i22 V1.0.0.3(4687). CVSS 3.1 is 7.5 with AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, indicating network-reachable, unauthenticated availability impact. Sources do not identify a fixed version.

Likely exposure

Exposure is likely limited to Tenda i22 devices running firmware V1.0.0.3(4687), especially where the management interface is reachable from untrusted networks. The CVE record’s normalized affected-product fields are incomplete, so asset validation should rely on device model and firmware evidence.

Exploitation context

The CVE is not listed as CISA KEV in the provided bundle, and no cited source confirms active exploitation. A public GitHub write-up is referenced, so vulnerability details are public, but exploitation status remains unconfirmed from the provided evidence.

Researcher notes

Evidence is sparse. The CVE record names the vulnerable function and parameter, CVSS vector, and one GitHub reference, but affected CPE/vendor fields are n/a and no fixed release is cited. Avoid broad product claims beyond Tenda i22 V1.0.0.3(4687).

Mitigation direction

  • Identify Tenda i22 devices and confirm firmware versions.
  • Check Tenda or device supplier guidance for fixed firmware.
  • Apply vendor-provided firmware if available.
  • Restrict management access to trusted admin networks or VPN.
  • Block internet exposure for affected device administration interfaces.
  • Monitor affected devices for crashes, restarts, or service instability.

Validation and detection

  • Inventory network devices for Tenda i22 model identifiers.
  • Record firmware version and compare against V1.0.0.3(4687).
  • Confirm admin interfaces are not reachable from the internet.
  • Review firewall rules limiting access to management services.
  • Check monitoring for unexplained device reboots or outages.
  • Track vendor advisories because sources do not name a fix.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-120: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2022-45671 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
7.5 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
7.5CVSS 3.1HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H3.93.6Primary CVE score

Vulnerability scoring details

Base CVSS 3.1 score

7.5High
CVSS 3.1 vector shape for CVE-2022-45671Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-120 · source CWE mapping

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.