Impact
A buffer overflow exists in the sub_432580 function of the /goform/fast_setting_wifi_set page on Tenda TX9 routers up to firmware 22.03.02.10_multi. By manipulating the SSID parameter, an attacker can overflow a buffer on the device, potentially leading to remote code execution or denial of service. The flaw is categorized as CWE‑119 and CWE‑120, indicative of an unsafe buffer handling vulnerability.
Affected Systems
The vulnerability affects Tenda TX9 router models with firmware versions older than or equal to 22.03.02.10_multi. Users operating these routers should verify their firmware revision and update to a patched release when one becomes available.
Risk and Exploitability
The CVSS base score of 8.7 highlights high severity. With an EPSS score below 1 % and no presence in the CISA KEV catalog, current exploitation likelihood is low; however, the flaw is publicly disclosed and the attack can be launched remotely via the wireless configuration interface, as the input is received over the network. If exploited, an attacker could gain arbitrary code execution on the device or disrupt network services.
OpenCVE Enrichment