Impact
A buffer overflow flaw exists in the httpd component of Tenda F453 firmware 1.0.0.3, specifically in the fromNatStaticSetting function that processes the page argument in /goform/NatStaticSetting. Malicious manipulation of this argument can corrupt memory and potentially allow an attacker to execute arbitrary code on the device. The vulnerability does not require local access and can be triggered from any remote host that can reach the router’s web interface.
Affected Systems
The flaw affects Tenda routers marketed as the F453 model running firmware 1.0.0.3. No other hardware or firmware versions are listed as vulnerable in the available data.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity, and the EPSS score of less than 1% suggests a low current exploitation probability, though the vulnerability has been disclosed publicly and an exploit is available. Because the issue is exploitable remotely and can lead to full compromise of the device, the risk remains significant. The vendor’s status is not included in CISA’s KEV catalog, but the lack of a patch in this firmware version creates a clear window for attackers to target affected systems.
OpenCVE Enrichment