Impact
A stack-based buffer overflow (CWE-119, CWE-121) exists in the fromwebExcptypemanFilter function of the Tenda F453 firmware. Manipulating the 'page' argument in the /goform/webExcptypemanFilter API can corrupt the stack and enable an attacker to execute arbitrary code. This flaw can compromise confidentiality, integrity, and availability of the device and any network services it supports.
Affected Systems
The vulnerability affects Tenda F453 routers running firmware version 1.0.0.3. No other product variants are listed as affected.
Risk and Exploitability
The flaw carries a CVSS score of 8.7, indicating high severity. The EPSS score is below 1%, suggesting a low probability of exploitation in the wild today. It is not yet listed in CISA’s KEV catalog. According to the description, the attack vector is remote, meaning an external attacker can trigger the overflow over the network.
OpenCVE Enrichment