Impact
A stack-based buffer overflow was discovered in the set_local_time_0 function of the Tenda W12 firmware. The overflow occurs when the Time argument supplied to the /bin/httpd component is manipulated, allowing an attacker to corrupt memory on the device stack. Successful exploitation can lead to arbitrary code execution from a remote host, as the vulnerability resides in a web‑based service that can be accessed over the network.
Affected Systems
The vulnerability affects Tenda W12 devices running firmware version 3.0.0.7(4763). No other vendor or product versions are presently listed as impacted.
Risk and Exploitability
The CVSS score of 8.7 marks this flaw as high severity, and the exploit is already publicly available. EPSS information is not available, so the current likelihood of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote, taking advantage of the HTTP interface to trigger the overflow.
OpenCVE Enrichment