Impact
The Tenda TX9 firmware possesses a denial of service flaw in the update_dev_name function of the /goform/SetOnlineDevName endpoint. The resource exhaustion condition that can make the device unresponsive. This weakness is categorized as CWE‑400 and compromises the availability of the router for any connected users.
Affected Systems
Affected devices include the Tenda TX9 router running firmware version V22.03.02.20. The vulnerability was documented by Tenda's own download page and an online advisory that references the /goform/SetOnlineDevName path.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity level, while the EPSS score of less than 1% signals a very low but non‑zero likelihood of exploitation in the wild. The flaw is not listed in CISA's KEV catalog. The likely attack vector involves remotely crafting requests to the /goform/SetOnlineDevName endpoint, but this is inferred from the description and not explicitly stated. No additional exploitation prerequisites are noted in the description.
OpenCVE Enrichment