Impact
A stack-based buffer overflow exists in the fromSetWifiGusetBasic function within the /goform/WifiGuestSet interface of Tenda JD12L firmware 16.03.53.23. Manipulating the shareSpeed argument triggers the overflow, allowing an attacker to potentially execute arbitrary code on the device. Affected systems are exposed to remote exploitation, as the attack can be initiated over the network without local access. The vulnerability carries a CVSS score of 8.7, indicating high severity. The publicly available exploit could lead to full compromise of the router, including data interception, network manipulation, and persistence. Given that the exploit is public and no designated fix is listed yet, administrators should treat this as a critical threat, especially for networks where the device is exposed to untrusted hosts.
Affected Systems
Tenda JD12L routers running firmware version 16.03.53.23 are affected. No other versions or variants were mentioned in the provided data.
Risk and Exploitability
The CVSS score of 8.7 reflects considerable damage potential. With no EPSS score available, the likelihood of exploitation remains unknown, but the public nature of the exploit and absence from KEV suggests the threat is real but possibly limited by exposure. Attackers could exploit the remote vulnerability to gain code execution, but precise prerequisites beyond network access were not detailed.
OpenCVE Enrichment