Impact
This vulnerability is a stack-based buffer overflow that occurs in the Saveqqlist function when handling the qqStr and markStr parameters. The overflow can be triggered by sending a specially crafted HTTP request, which allows an attacker to crash the device’s web management interface and cause a denial of service. The flaw is an example of insufficient input validation that leads to memory corruption.
Affected Systems
The affected product is the Shenzhen Tenda Technology Co., Ltd Tenda G0 router running firmware version 15.11.0.5. No other versions were listed in the report.
Risk and Exploitability
No EPSS score or CVSS value was published, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote over the network, targeting the device’s HTTP management interface. An attacker with network access can craft a malicious payload that overflows the buffer, triggering an application crash and disrupting service availability.
OpenCVE Enrichment