Impact
The Tenda W12 router firmware exposes a flaw in the cgistaKickOff function of the /bin/httpd binary. Manipulating the staMac argument can trigger a stack-based buffer overflow, and a published exploit demonstrates the capability to take control of the device. This type of vulnerability can compromise confidentiality, integrity, and availability by allowing an attacker to execute arbitrary code on the router.
Affected Systems
Tenda W12 routers running firmware version 3.0.0.7(4763) are vulnerable. The issue is confined to the httpd process on these devices and does not affect other Tenda products or firmware releases outside this version range.
Risk and Exploitability
The CVSS score of 8.7 signifies a high severity risk. Although no EPSS score is provided, the vulnerability is not listed in the CISA KEV catalog, yet an exploit has been published and can be delivered remotely by manipulating the staMac parameter. The stack overflow can be leveraged for remote code execution, making this a critical threat for any network that hosts the affected router without adequate protection.
OpenCVE Enrichment