Impact
A vulnerability in firmware 300001138_en_xpon of Tenda HG7, HG9, and HG10 routers exposes a stack‑based buffer overflow in the Web Management Interface. The flaw affects the asp_voip_OtherSet function exposed at /boaform/voip_other_set. Manipulating the funckey_transfer argument overflows the stack, potentially enabling arbitrary code execution with the web service’s privileges. The weakness conforms to CWE‑119 and CWE‑121.
Affected Systems
The affected devices are Tenda HG7, HG9, and HG10 routers running firmware version 300001138_en_xpon, distributed by Tenda. The vulnerability resides in the web interface component and is triggered by requests to the voip_other_set endpoint.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, and the EPSS score of 4% suggests a moderate probability of exploitation in the wild. Based on the description, it is inferred that the exploit can be carried out remotely via the router’s web management interface and that authentication is not explicitly required, so the endpoint is likely publicly reachable from any host that can connect to the service. The vulnerability is not currently listed in CISA’s KEV catalog, but its remote reach and high severity demand prompt remediation.
OpenCVE Enrichment