Impact
A stack-based buffer overflow exists in the Tenda F453 firmware 1.0.0.3, triggered by manipulation of the GO parameter on the /goform/WrlExtraSet endpoint. The overflow can be exploited remotely to execute arbitrary code, leading to full control of the device. The vulnerability has been publicly disclosed and may be used by attackers.
Affected Systems
Tenda F453 router running firmware version 1.0.0.3. No additional versions are currently known to be affected.
Risk and Exploitability
The CVSS score of 8.7 indicates a high-impact flaw with high severity. EPSS indicates a very low, but non-zero, exploitation probability of less than 1 percent. The vulnerability is not listed in CISA’s KEV catalog. Exploitation is possible over a remote network, likely via the router’s web interface, and would allow an attacker to achieve remote code execution on the device.
OpenCVE Enrichment