Impact
A stack‑based buffer overflow exists in the fromAddressNat function of the /goform/addressNat endpoint on the Tenda JD12L router. The flaw is triggered by manipulating the page argument, which can overflow the stack and potentially allow arbitrary code execution. The vulnerability is classified as a high‑severity flaw, with a CVSS score of 8.7, and the exploit has been publicly disclosed.
Affected Systems
The affected device is the Tenda JD12L router running firmware version 16.03.53.23. No other vendors or product versions are listed as impacted.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, and while EPSS data is not available, the lack of a KEV listing does not imply the vulnerability has been exploited in the wild as of now. The likelihood of exploitation is judged to be moderate based on the public disclosure and remote nature of the attack vector. The attack vector is inferred to be remote, via the web interface exposed on the router, and could allow an unauthenticated attacker who can reach the endpoint to achieve full code execution.
OpenCVE Enrichment