Impact
A buffer overflow exists in the goform/formSetMacFilterCfg handler of the Tenda AC15 V15.03.05.18_multi firmware. This flaw allows an attacker who can send a specially crafted request to the router’s configuration interface to overwrite memory on the device. If exploited, the attacker could gain arbitrary code execution, compromising the integrity and confidentiality of the router and potentially the devices connected to it.
Affected Systems
The vulnerability affects the Tenda AC15 router model, specifically firmware version 15.03.05.18_multi. System administrators managing devices listed under the hardware identifier ac15 v1.0 should verify that they are running this firmware or a newer patched release.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity, while the EPSS score of less than 1% suggests low available exploitation probability at the time of analysis. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, so no confirmed exploits are publicly known. Nonetheless, the attack vector is inferred to be remote via the router’s HTTP management interface; an attacker could construct a request without authentication if the interface is exposed to the public network or accessed by an untrusted internal user. Given its high impact, the potential for remote code execution remains a top concern for any organization still running the affected firmware.
OpenCVE Enrichment