Impact
A buffer overflow exists in the fromSafeEmailFilter function used by the SafeEmailFilter component of the Tenda F453 router’s httpd service. By manipulating the page parameter in the /goform/SafeEmailFilter endpoint, a remote attacker can overwrite adjacent memory and execute arbitrary code, potentially granting full control of the device. The vulnerability is a classic memory corruption flaw, classified as CWE‑119 and CWE‑120, and carries a high CVSS score of 8.7.
Affected Systems
The flaw affects the Tenda F453 router running firmware version 1.0.0.3. No other firmware releases or product models are listed as affected in the current CNA data.
Risk and Exploitability
The CVSS score of 8.7 reflects a high‑severity threat, while the EPSS score of less than 1% indicates a low probability of exploitation at the time of analysis. Based on the description, it is inferred that the attack vector is remote via HTTP, and the vulnerability does not explicitly require authentication or local privileges. A publicly disclosed exploit is available, suggesting that the risk is real and may materialize soon. The vulnerability is not currently catalogued in the CISA KEV list, but the combination of high impact and known public exploitation warrants immediate remediation.
OpenCVE Enrichment