Impact
A stack overflow occurs in the save_list_data parameter of the formSetCfm function in Tenda O3v3 firmware. The overflow is triggered by a crafted HTTP request, causing the device to crash and cease responding, which results in a loss of availability for the affected system. No impact on confidentiality or integrity is described.
Affected Systems
Shenzhen Tenda Technology Co., Ltd’s Tenda O3v3 model running firmware version 1.0.0.5 is confirmed affected; other nearby firmware releases may be impacted but are not explicitly listed.
Risk and Exploitability
The vulnerability is exploitable remotely via the web interface and can be triggered simply by sending a malicious HTTP request. EPSS is not available and the issue is not listed in CISA KEV, indicating that while the tool shows no known active exploits, the risk remains high for causing disruption to networked services. The lack of a CVSS score limits quantification, but the potential for widespread availability loss warrants prompt mitigation.
OpenCVE Enrichment