Impact
The Tenda TX9 V22.03.02.20 firmware contains a buffer overflow in the sub_425964 function that processes the online device name via the /goform/SetOnlineDevName interface, allowing a crafted input to overwrite the stack and potentially execute arbitrary code, a flaw classified as CWE-121 and rated with a CVSS score of 9.8, indicating critical severity.
Affected Systems
The vulnerable device is the Tenda TX9 wireless router running firmware version V22.03.02.20; no additional versions are documented as affected in the provided information.
Risk and Exploitability
Although the EPSS score is below 1%, indicating rare exploitation at present, the high CVSS score and absence from CISA KEV do not mitigate the significant risk; based on the description, it is inferred that attackers could target the publicly exposed management interface to deliver malicious device names, trigger the stack overflow, and potentially gain remote code execution capabilities on the router, especially in networks where the web interface is accessible locally.
OpenCVE Enrichment