Impact
A flaw in the formWriteFacMac function of the Tenda F451 Web Management Interface allows a crafted mac parameter to inject and execute arbitrary OS commands. This can enable an attacker to run commands on the router, posing a serious threat to the device’s integrity, availability, and potentially the internal network it serves. The issue is classified as CWE‑77 and CWE‑78, reflecting unsafe command construction and execution.
Affected Systems
The vulnerability affects Tenda F451 routers running firmware versions 1.0.0.7 and 1.0.0.9. It resides in the Web Management Interface component exposed via the /goform/WriteFacMac endpoint.
Risk and Exploitability
The EPSS score of 2% indicates a low probability of exploitation. The CVSS score of 8.7 signals high severity. Since the exploit is publicly available and the vulnerable endpoint can be reached remotely, an attacker who succeeds can run arbitrary OS commands, compromising device integrity. While the overall exploitation likelihood is low based on EPSS, the potentially severe impact justifies immediate remediation.
OpenCVE Enrichment