Impact
A stack-based buffer overflow exists in the cgiSysTimeInfoSet function of the Tenda W12 firmware 3.0.0.7(4763). By sending a crafted value for the sec argument to the /bin/httpd handler, an attacker can overwrite return addresses on the stack, which typically enables arbitrary code execution. The vulnerability is classified as CWE‑119 and CWE‑121 and can compromise confidentiality, integrity, and availability of the device when exploited.
Affected Systems
The affected device is the Tenda W12 wireless router running firmware version 3.0.0.7(4763). Only this specific firmware release has been confirmed to contain the flaw; newer releases may have addressed the issue.
Risk and Exploitability
The CVSS v3 score of 8.7 indicates high severity, yet the EPSS score is not available and the issue is not yet listed in the CISA KEV catalog. Exploitation is remotely feasible via the device's HTTP management interface and has already been publicly disclosed, implying that an attacker can trigger the overflow from any network with access to the router's management port. The combination of remote triggerability and the high impact rating results in a significant risk until a patch or mitigation is applied.
OpenCVE Enrichment