Impact
The vulnerability in Tenda HG9 firmware 300001138 allows an attacker to send a specially crafted pingAddr argument to the /boaform/formPing endpoint, causing a buffer overflow on the device’s stack. This flaw can lead to arbitrary code execution from a remote host, compromising confidentiality, integrity, and availability of the network device.
Affected Systems
The affected device is the Tenda HG9 model running firmware version 300001138. Any installation of this firmware that exposes the Diagnostic Ping Endpoint to external networks is vulnerable. The vulnerability is specific to the formPing component and requires the device to be reachable over the network.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. The EPSS score of less than 1% indicates a very low but non‑zero probability of exploitation, possibly due to targeted actors. The flaw is not listed in CISA’s KEV catalog, implying no known widespread exploitation. However, the remote nature of the attack and the potential for arbitrary code execution make it a high‑risk threat if left unmitigated. An attacker would need network access to the device and could exploit the overflow simply by crafting an HTTP request to /boaform/formPing with an oversized pingAddr parameter.
OpenCVE Enrichment