Impact
A stack-based buffer overflow occurs in the fromNatStaticSetting function on the Tenda FH1202 router. By manipulating the page argument to the /goform/NatSaticSetting endpoint, a remote attacker can overflow a buffer on the stack. This flaw may allow execution of arbitrary code, compromise device integrity, and potentially provide a foothold for further network attacks. The vulnerability directly threatens confidentiality and availability of the affected system.
Affected Systems
The vulnerability affects the Tenda FH1202 router running firmware version 1.2.0.14(408). This includes devices identified by the CPE strings cpe:2.3:h:tenda:fh1202:-:*:*:*:*:*:*:* and cpe:2.3:o:tenda:fh1202_firmware:1.2.0.14(408):*:*:*:*:*.*
Risk and Exploitability
The CVSS score of 8.7 denotes a high severity, and the EPSS score of < 1% indicates a very low yet nonzero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, but its exploit has been published and may be used. The attack vector is inferred to be remote, as the flaw can be triggered over a network connection to the router's web interface.
OpenCVE Enrichment