Impact
The Tenda TX9 firmware version V22.03.02.05 contains a stack-based buffer overflow in the sub_4418CC function within the /goform/SetNetControlList endpoint, identified as CWE-121. This flaw can allow an attacker to overwrite critical memory areas and potentially execute arbitrary code on the device, compromising confidentiality, integrity, and availability of the network appliance.
Affected Systems
The vulnerability affects Tenda TX9 routers running firmware V22.03.02.05. No other vendors or product versions are listed as impacted.
Risk and Exploitability
The CVSS score of 9.8 classifies this issue as critical. Although the EPSS score is below 1%, indicating a low probability of widespread exploitation at this time, the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the /goform/SetNetControlList HTTP endpoint. Based on the description, it is inferred that an attacker with network reach could trigger the stack overflow to gain control of the device. Given the severity, a remote adversary with network reach could potentially exploit this flaw to compromise confidentiality, integrity, and availability of the device.
OpenCVE Enrichment