Impact
The vulnerability is a classic buffer overflow that occurs when an attacker supplies an excessively long rebootTime value to the SetSysAutoRebbotCfg form. Because the input is not properly bounded, the overflow can corrupt adjacent memory, leading to unpredictable behavior including denial of service or arbitrary code execution. This weakness falls under CWE-119 and CWE-120, indicating unbounded buffer handling and improper management of user‑controlled data.
Affected Systems
The affected device is the Tenda AC12 router running firmware version 15.03.06.23_multi_TD01. Only this member of the AC12 line, as identified by the vendor name and firmware identifier, is known to contain the vulnerable function /goform/SetSysAutoRebbotCfg in its httpd web management component.
Risk and Exploitability
The CVSS score of 8.7 classifies the flaw as high severity. The EPSS score is currently unavailable, so the likelihood of exploitation cannot be quantified from the data. The vulnerability is not listed in CISA's KEV catalog. The description states that the attack may be initiated remotely, implying the attacker can exploit the flaw over the network without local access. Given that the buffer overflow can lead to code execution, the risk to any remote user of the device is significant.
OpenCVE Enrichment