Impact
A buffer overflow occurs in the picCropName parameter of the formCropAndSetWewifiPic function, allowing an attacker to send a crafted HTTP request that triggers a crash of the target process. The flaw does not provide remote code execution or data exfiltration; its effect is limited to disrupting the service, resulting in a denial of service. The weakness corresponds to an uncontrolled buffer write, classifiable as a classic buffer overflow.
Affected Systems
Shenzhen Tenda Technology Co., Ltd Tenda W15E firmware version 15.11.0.10 is vulnerable. No other affected firmware versions are documented in the available data.
Risk and Exploitability
The vulnerability can be exploited by sending a specifically formatted HTTP request to the formCropAndSetWewifiPic endpoint. The CVSS score is 7.5, and the EPSS score is < 1%, indicating a very low likelihood of exploitation. The vulnerability is not listed in CISA's KEV catalog, implying that no publicly confirmed exploits have been reported yet.
OpenCVE Enrichment