Impact
A stack-based buffer overflow exists in the formQuickIndex endpoint of Tenda FH451 firmware. By manipulating the mit_linktype or PPPOEPassword fields, an attacker can overflow the device’s stack, potentially allowing remote code execution. The vulnerability is exploitable via HTTP requests, and publicly available exploits are known.
Affected Systems
Tenda FH451 routers running firmware version 1.0.0.9 are affected. No other product models or firmware versions are explicitly listed as vulnerable.
Risk and Exploitability
The CVSS score of 8.7 signals a high severity vulnerability. The EPSS score of less than 1% indicates a low current exploitation probability. The case is not included in the CISA KEV catalogue, suggesting no confirmed active attacks yet. The flaw can be triggered remotely by sending crafted HTTP requests to /goform/QuickIndex, so an adversary with network or internet access to the router could exploit it.
OpenCVE Enrichment