Impact
A stack overflow exists in the username parameter of the R7WebsSecurityHandler function in the firmware of Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router. By supplying a specially crafted HTTP request with an oversized or malformed username field, an attacker can trigger a buffer overflow that causes the device to crash and become unavailable. This flaw is a classic buffer overflow weakness, which compromises device stability but does not provide direct code execution capability.
Affected Systems
The vulnerability affects the Tenda O3 Wireless Router running firmware version 1.0.0.5(4180). No other vendor or product versions are known to be impacted at this time.
Risk and Exploitability
The vulnerability can be exploited remotely over the Internet by sending a malicious HTTP request to the R7WebsSecurityHandler endpoint; authentication is not required. Because the flaw causes a crash, it represents a high denial‑of‑service risk to the network served by the router. The EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog. While no CVSS score is provided, the description indicates a severe impact on network availability.
OpenCVE Enrichment