Impact
The flaw is a stack‑based buffer overflow in the fromSetCfm function found in /goform/setcfm of Tenda F453 firmware. By carefully crafting the arguments funcname/funcpara1, an attacker can overflow the local buffer, potentially allowing arbitrary code execution on the router. The description explicitly states that remote exploitation is possible, indicating that an attacker only needs network access to trigger the overflow.
Affected Systems
The vulnerability affects the Tenda F453 router, specifically firmware versions 1.0.0.3 and 1.If. The affected component is the fromSetCfm function in the firmware’s /goform/setcfm endpoint.
Risk and Exploitability
With a CVSS score of 8.7, this is a high‑severity vulnerability. The EPSS score is reported as less than 1%, suggesting a low likelihood of exploitation in the wild, but the publicly disclosed exploit means it could be used nonetheless. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to access the device over the network, sending the crafted input to trigger the buffer overflow and achieve remote code execution.
OpenCVE Enrichment