Impact
A stack-based buffer overflow exists in the Tenda AC1206 firmware version 15.03.06.23_multi_TD01, triggered by manipulating the devName parameter in the /goform/SetOnlineDevName endpoint of the httpd web management interface. The flaw allows an attacker to corrupt the call stack, potentially leading to arbitrary code execution or a denial‑of‑service condition. The weakness is classified under CWE‑119 and CWE‑121.
Affected Systems
Systems using the Tenda AC1206 router, specifically the 15.03.06.23_multi_TD01 firmware build, are affected. The vulnerability is accessed through the router’s web management interface, which is typically exposed on ports 80/443 and may be reachable from the internet or local network. Users relying on the default or publicly accessible admin control panel are at risk.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, while no EPSS data is provided. The vulnerability is publicly exploitable and has a known remote attack path. Because the exploit is available, attackers can target any accessible device without skill, making the risk significant. The lack of inclusion in the CISA KEV catalog does not diminish the likelihood of active exploitation; security teams should treat this as an urgent risk.
OpenCVE Enrichment