Impact
A buffer overflow flaw exists in the Tenda F453 router’s httpd component, specifically the formWebTypeLibrary function that processes the webSiteId argument. When an attacker sends a crafted value for this parameter, the uncontrolled overwrite can lead to arbitrary code execution on the device. The description indicates that the flaw can be triggered remotely, and a public exploit has already been released, highlighting the vulnerability’s potential for high‑impact attacks.
Affected Systems
The vulnerable product is the Tenda F453 wireless router running firmware version 1.0.0.3. No other vendors or product lines are listed as affected.
Risk and Exploitability
The vulnerability has a CVSS score of 8.7, classifying it as high severity, and an EPSS score of less than 1 %. While the current exploitation probability is low, the public availability of an exploit and the remote nature of the attack vector raise the overall risk. The flaw is not present in the CISA KEV catalog, but admins should treat it with urgency because the exposure could compromise the device and any networks connected through it.
OpenCVE Enrichment