Impact
A stack-based buffer overflow exists in the cgiWifiMacFilterSet function of the Tenda W12 router firmware, specifically crafted by supplying a malformed wifiMacFilterSet.mac argument. The flaw can allow remote attackers to corrupt the stack, potentially executing arbitrary code on the device with privileges of the httpd process. Based on the disclosed attack method, the vulnerability is exploitable over the network by sending crafted HTTP requests to the router's web interface, confirming a remote exploitation vector.
Affected Systems
Tenda W12 routers running firmware version 3.0.0.7 (build 4763) are affected. No other models or firmware releases are known to be impacted.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, combining high impact on confidentiality, integrity, and availability with a remote attack vector. EPSS data is not available, so the exact likelihood of exploitation is uncertain, but the vulnerability is publicly disclosed and a proof‑of‑concept has been released. It is not currently listed in the CISA KEV catalog. Given the remote nature of the exploit and the lack of mitigation, the risk to affected devices warrants urgent action.
OpenCVE Enrichment