Impact
A buffer overflow occurs in the picCropName parameter of the formCropAndSetWewifiPic function, allowing an attacker to send a crafted HTTP request that triggers a crash of the target process. The flaw does not provide remote code execution or data exfiltration; its effect is limited to disrupting the service, resulting in a denial of service. The weakness corresponds to an uncontrolled buffer write, classifiable as a classic buffer overflow.
Affected Systems
Shenzhen Tenda Technology Co., Ltd Tenda W15E firmware version 15.11.0.10 is vulnerable. No other affected firmware versions are documented in the available data.
Risk and Exploitability
The vulnerability can be exploited by sending a specifically formatted HTTP request to the formCropAndSetWewifiPic endpoint. No CVSS score is published, and the EPSS score is unavailable, making the precise risk level difficult to quantify. The vulnerability is not listed in CISA's KEV catalog, implying that no publicly confirmed exploits have been reported yet.
OpenCVE Enrichment