Impact
The vulnerability is a stack overflow triggered by an oversized value in the param_1 parameter of the formSetCfm function. A malicious HTTP request can invoke this overflow, exhausting stack resources and causing the router to crash or become unresponsive. This results in a loss of network availability for devices that depend on the router for connectivity.
Affected Systems
Shenzhen Tenda Technology Co., Ltd provides the Tenda W3 Wireless Router, firmware version 1.0.0.3(2204). Users running that firmware are exposed until they apply a newer, fixed release.
Risk and Exploitability
The flaw can be triggered remotely via a standard HTTP request, so no privileged credentials are required. Based on the description, it is inferred that the attacker sends a crafted HTTP request to the vulnerable endpoint. The EPSS score of less than 1% indicates a very low but nonzero likelihood of exploitation in the wild, and the CVSS score of 6.5 reflects a moderate severity. The vulnerability is not listed in the CISA KEV catalog, but repeated exploitation could lead to sustained outages in environments that rely on the router for connectivity.
OpenCVE Enrichment