Impact
A stack-based buffer overflow has been discovered in the ipMacBindListStore function of the Tenda W20E firmware 15.11.0.6(1068_1546_841)_CN_TDC. The vulnerability is exposed through manipulation of the IPMacBindRule argument in the /goform/addIpMacBind endpoint. Exploitation of this flaw can lead to arbitrary code execution on the device, compromising its confidentiality, integrity, and availability. The weakness is categorized as CWE-119 and CWE-121, both involving unsafe buffer handling and stack-based overflows.
Affected Systems
The affected device is the Tenda W20E router. Vulnerable firmware versions include 15.11.0.6(1068_1546_841)_CN_TDC; no other firmware or model information is provided in the entry.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. No EPSS data is available, but the publicly released exploit and the ability to attack remotely raise the likelihood of real-world exploitation. The vulnerability is not listed in CISA KEV, but the public availability of an exploit suggests an urgent need to address the flaw.
OpenCVE Enrichment