Impact
The vulnerability is a stack overflow in the IPMacBindRuleIp parameter of the formIPMacBindModify function in Tenda G0 firmware. When an attacker sends a crafted HTTP request, the overflow corrupts stack memory and causes the device to crash, resulting in a denial of service. The flaw stems from improper bounds checking – a classic buffer overflow scenario.
Affected Systems
Shenzhen Tenda Technology Co., Ltd Tenda G0 version 15.11.0.5 is affected. No other versions or products were listed.
Risk and Exploitability
The attack vector is remote over HTTP, allowing any unauthenticated user on the network or internet if the device is exposed to attack. The CVSS score is not provided, and EPSS is unavailable, but the lack of a security fix and the possibility of widespread DoS keep the risk relatively high. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment