Impact
A stack‑based buffer overflow exists in the Tenda G0 web management interface, specifically within the formSetPortMirror function that processes the portMirrorMirroredPorts parameter. This vulnerability enables an attacker to corrupt data on the stack and send malicious payloads through HTTP POST requests to the /goform/module endpoint. If the overflow succeeds, the attacker could obtain the privileges of the web server process, allowing execution of arbitrary code on the device.
Affected Systems
All Tenda G0 routers with firmware versions up to 20260625 are affected. The flaw is confined to the httpd component’s handling of formSetPortMirror requests and does not depend on any specific model within the G0 series.
Risk and Exploitability
The CVSS score of 8.7 classifies this vulnerability as high severity, and an exploit is publicly available, indicating a real threat. Although the EPSS score is not reported and the issue is not yet listed in the CISA KEV catalog, the remote nature of the attack and the possibility of arbitrary code execution mean that routers remain highly vulnerable until a fix is applied.
OpenCVE Enrichment