Impact
A stack overflow occurs in the save_list_data parameter of the formSetCfm function in Tenda O3v3 firmware. The overflow is triggered by a crafted HTTP request, causing the device to crash and cease responding, which results in a loss of availability for the affected system. No impact on confidentiality or integrity is described.
Affected Systems
Shenzhen Tenda Technology Co., Ltd’s Tenda O3v3 model running firmware version 1.0.0.5 is confirmed affected; other nearby firmware releases may be impacted but are not explicitly listed.
Risk and Exploitability
The vulnerability is exploitable remotely via the web interface and can be triggered simply by sending a malicious HTTP request. The EPSS score of <1% indicates a low but non-zero exploitation probability, and the issue is not listed in CISA KEV, so no known active exploits are documented; nevertheless, the residual risk remains high for causing disruption to networked services. The CVSS score of 7.5 quantifies the severity, but the potential for widespread availability loss warrants prompt mitigation.
OpenCVE Enrichment