Impact
The vulnerability is a stack‑based buffer overflow in the formPPPEdit function of the Tenda HG7, HG9, and HG10 routers. It is triggered by manipulating the encodename argument in the /boaform/formPPPEdit endpoint. This flaw falls under CWE‑119 and CWE‑121 and can lead to arbitrary code execution when exploited. The exploit is publicly available and can be launched remotely, allowing an attacker to compromise the device.
Affected Systems
Affected products include Tenda HG7, HG9 and HG10 routers running firmware 300001138_en_xpon. Users of these models are at risk if they have not patched the firmware or restricted remote access to the device’s management interface.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.7, indicating high severity. The EPSS score is < 1 %, but the exploit is publicly available and can be launched remotely, indicating a considerable risk of exploitation. The flaw is not listed in CISA’s KEV catalog, yet its potential for remote code execution makes immediate action advisable.
OpenCVE Enrichment