Impact
The vulnerability is a stack overflow in the Go parameter of the ask_to_reboot function (CWE-121). It can be triggered by a crafted input that causes the firmware to crash, resulting in a denial of service. The flaw leads to an uncontrolled memory overwrite that terminates the process handling the request.
Affected Systems
Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router, firmware version v1.0.0.3(2204).
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, but stack overflows typically allow attackers to force a device to reboot or become unresponsive. The EPSS score is < 1% and the vulnerability is not listed in CISA KEV. The likely attack vector is local network traffic directed to the router, requiring an attacker to send a specifically crafted request to the ask_to_reboot function.
OpenCVE Enrichment