Impact
A stack-based buffer overflow exists in the fromSetCfm function of the Tenda FH451 firmware 1.0.0.9, triggered by manipulating the funcname/funcpara1 arguments in the /goform/setcfm interface. The flaw permits a remote attacker to corrupt the stack, leading to uncontrolled behavior that could allow arbitrary code execution, thereby compromising device confidentiality, integrity, and availability. This vulnerability is classified as CWE-119 and CWE-121.
Affected Systems
The vulnerability affects Tenda FH451 routers running firmware version 1.0.0.9. No other versions have been confirmed to be impacted at this time.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity, while the EPSS score of less than 1% suggests a low current likelihood of exploitation. The flaw can be triggered remotely via the web interface, but the exploit requires sending a crafted payload to the setcfm endpoint. The vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment