Impact
A buffer overflow exists in the httpd component of Tenda F453 firmware 1.0.0.3, specifically in the fromNatStaticSetting function that processes the page argument used in the /goform/NatStaticSetting interface. Malicious manipulation of this argument can corrupt memory. The vulnerability can be exploited remotely by any host that can reach the router’s web interface, and no local access is required. The exploit is publicly available. Based on the description, it is inferred that the attack vector is remote access to the router’s web interface.
Affected Systems
The flaw affects Tenda F453 routers running firmware version 1.0.0.3. No other hardware or firmware versions are listed as vulnerable in the available data.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity, and the EPSS score of 3% suggests a low current exploitation probability, although an exploit exists in the wild. The vulnerability is remotely exploitable without local access, and the impact depends on the effect of the buffer overflow when executed. The vulnerability is not listed in CISA KEV, but the lack of a patch in this firmware version creates a clear window for attackers to target affected systems. Based on the vulnerability’s ability to be exploited remotely, it is inferred that the attack vector is remote.
OpenCVE Enrichment