Impact
A buffer overflow flaw exists in the frmL7ImForm function of the Tenda F453 router firmware 1.0.0.3. By manipulating the page argument supplied to the /goform/L7Im endpoint, an attacker can cause a memory overrun that may allow arbitrary code execution or denial of service on the device. The vulnerability carries a CVSS score of 8.7, indicating high severity, and the description explicitly states it can be exploited remotely.
Affected Systems
The vulnerability affects the Tenda F453 router running firmware version 1.0.0.3. No other firmware versions or Tenda products are identified as impacted in the provided data.
Risk and Exploitability
The low EPSS score of less than 1% suggests that current exploit activity is rare, and the issue is not listed in the CISA KEV catalog. Nevertheless, the flaw is publicly documented and an exploit exists, allowing attackers with remote access to the router’s management interface to construct a malicious request to /goform/L7Im and trigger the overflow. Compromise could grant the attacker control of the device or disrupt network services. No special privileges or local access are required, making the threat straightforward for attackers with external network visibility.
OpenCVE Enrichment