Impact
A stack overflow occurs in the SetVirtualServerCfg helper of the Tenda TX9 firmware. This overflow can overwrite control data on the stack when overly long configuration strings are submitted, potentially allowing an attacker to corrupt control flow or execute arbitrary code. Because the vulnerability exists in a gateway device that handles network traffic, exploitation could compromise confidentiality, integrity, and availability of the device and the network it serves. The weakness is identified as CWE-121.
Affected Systems
The flaw is present in Tenda TX9 routers running firmware version V22.03.02.20. No other product or version information has been disclosed. Vendors or distributors of this firmware should verify whether newer releases address the issue.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity, while the EPSS of less than 1% suggests that exploitation is presently uncommon. The vulnerability is not yet listed in the CISA KEV catalog. The attack likely proceeds over the network by sending a crafted request to /goform/SetVirtualServerCfg, leveraging the device’s management interface. No authentication requirement is mentioned, so the request could be made from any host able to reach the router’s control port.
OpenCVE Enrichment