Impact
The vulnerability is caused by an unsafe use of the strcpy function in the /goform/exeCommand handler on Tenda F453 routers, leading to a stack-based buffer overflow that can be triggered by sending an oversized cmdinput string; the flaw is characterized by CWE-119 and CWE-121 and gives an attacker the ability to execute arbitrary code or commands on the device.
Affected Systems
Tenda F453 routers running firmware version 1.0.0.3 are affected; administrators should verify the precise firmware version on each device and confirm whether the product is from the Tenda F453 line.
Risk and Exploitability
The flaw carries a high CVSS score of 8.7 and, although the current EPSS probability is reported as less than 1 percent, a publicly disclosed exploit demonstrates that it can be abused remotely via the router’s HTTP interface; the vulnerability is not listed in the CISA KEV catalog, but its severity and remote reachability warrant immediate attention and mitigate the risk of full system compromise.
OpenCVE Enrichment