Impact
A stack overflow exists in the sub_424CE0 function within the /goform/setMacFilterCfg handler on Tenda TX9 firmware V22.03.02.20. This defect can corrupt the stack and potentially allow an attacker to modify execution flow, leading to arbitrary code execution. This vulnerability is a stack-based buffer overflow, identified as CWE‑121. The CVSS score of 9.8 classifies it as critical, indicating that if exploited, the attacker could gain full control over the device.
Affected Systems
The vulnerability affects Tenda TX9 routers running firmware version V22.03.02.20. No other firmware versions are listed, so that is the only known affected build.
Risk and Exploitability
The low EPSS (< 1%) suggests that the exploit is not widely available or actively used, but the high CVSS score indicates that if an attacker finds a way to reach the /goform/setMacFilterCfg endpoint—likely through a web interface exposed to the Internet or internal LAN—they could trigger the overflow. The vulnerability is not listed in CISA’s KEV catalog, so no known public exploit has been documented. The attack would probably require an attacker to directly send crafted requests to the affected endpoint, and may or may not require authentication, though the description does not specify that requirement.
OpenCVE Enrichment