Impact
The vulnerability is a buffer overflow in the formAddWewifiWhiteUser function, triggered by an invalid wewifiWhiteUserInfo parameter. This flaw allows an attacker to overflow a memory buffer and crash the application, resulting in a denial of service. The weakness corresponds to CWE-119 – Buffer Overflow.
Affected Systems
Shenzhen Tenda Technology Co., Ltd provides the Tenda W15E router, firmware version 15.11.0.10, which is affected by this issue.
Risk and Exploitability
The vulnerability is triggered via a crafted HTTP request targeting the formAddWewifiWhiteUser endpoint. No EPSS score is available, and the issue is not listed in CISA KEV. Attackers need only be able to reach the vulnerable HTTP service to force the device into a DoS state. The impact is limited to availability for the device and any services relying on it.
OpenCVE Enrichment