Impact
This flaw is a stack‑based buffer overflow located in the parse_macfilter_rule function of the /goform/setBlackRule endpoint. An attacker can supply a specially crafted deviceList argument that overflows the stack, potentially allowing arbitrary code execution over the network. The vulnerability is disclosed publicly and can be exploited remotely, giving an attacker control over the affected router, which compromises confidentiality, integrity, and availability.
Affected Systems
The issue affects Tenda routers model A18 running firmware version 15.13.07.13. Devices with this firmware are vulnerable.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity. The EPSS value below 1% suggests the probability of exploitation is currently low, and the vulnerability is not listed in the CISA KEV catalog. However, because the exploit is remote and publicly available, administrators should treat it as a high‑risk threat, especially if the device exposes management interfaces to uncontrolled networks.
OpenCVE Enrichment