Impact
This vulnerability presents a stack-based buffer overflow in the formWrlsafeset function within the /goform/AdvSetWrlsafeset interface of Tenda FH1202 routers running firmware 1.2.0.14(408). By supplying crafted values for the mit_ssid/mit_ssid_index parameters, an attacker can overflow the local stack buffer. The CVE description does not specify the exact consequences, but a stack overflow can potentially allow the attacker to execute arbitrary code or cause a denial of service.
Affected Systems
Affected devices are Tenda FH1202 routers with firmware version 1.2.0.14(408). No other vendors, products, or firmware revisions are listed as impacted in the CNA or CPE entries.
Risk and Exploitability
The CVSS score of 8.7 marks the flaw as high severity; however, the EPSS score of less than 1% suggests a low current exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog, indicating no widespread exploitation yet. Attackers would need remote network access to the router’s web interface, specifically the /goform/AdvSetWrlsafeset endpoint, to craft the malicious mit_ssid input. The attack vector is described as remote, but the exact method of code execution remains unspecified.
OpenCVE Enrichment