Impact
The vulnerability is a buffer overflow in the fromSafeUrlFilter function of the Tenda F453 router. Manipulating the page argument in the /goform/SafeUrlFilter interface causes the device to write beyond allocated memory, which can be leveraged to execute arbitrary code on the router. The failure to enforce bounds checking represents a classic buffer overflow flaw, allowing attackers to potentially take full control of the device.
Affected Systems
The flaw affects Tenda’s F453 model running firmware version 1.0.0.3. No other models or firmware revisions are listed as vulnerable in the available data.
Risk and Exploitability
This issue carries a CVSS score of 8.7, indicating high severity, while the EPSS score is below 1 % reflecting a low current probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, but it has been publicly disclosed and can be triggered remotely by sending a crafted request to the web interface. An attacker who succeeds may gain remote code execution on the router, compromising network security.
OpenCVE Enrichment