Impact
A stack-based buffer overflow exists in the fromNatlimit function within the Web Management Interface of Tenda F451 routers. By manipulating the page argument sent to /goform/Natlimit, an attacker can overflow the stack and potentially execute arbitrary code. The vulnerability can be triggered remotely, and exploit code has already been made publicly available, which means a compromised router could become a foothold for further attacks.
Affected Systems
The flaw affects Tenda F451 routers running firmware 1.0.0.7 or 1.0.0.9. These versions are found in the router’s Web Management Interface component. No other firmware versions are reported to be impacted according to the current CNA data.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity vulnerability. EPSS is not available, but the public availability of exploit code raises the exploitation likelihood. The attack vector is remote via the web interface, and the vulnerability is listed in KEV as not present, reflecting no known mass exploitation yet. Nonetheless, the potential for remote code execution warrants prompt attention.
OpenCVE Enrichment