Impact
A stack-based buffer overflow flaw was discovered in the formWifiMacFilterGet function of Tenda i12 firmware 1.0.0.6(2204). The weakness is triggered by manipulating the argument index, allowing an attacker to overflow the stack when the /goform/WifiMacFilterGet endpoint is accessed; the flaw is exploitable remotely and public proof-of-concept exploits have been released.
Affected Systems
The vulnerability affects Tenda i12 routers running firmware version 1.0.0.6(2204). No other versions are listed in the CNA data, so only this build is confirmed vulnerable.
Risk and Exploitability
The CVSS v3 base score is 8.7, indicating high severity, and the EPSS score is reported as less than 1%, suggesting a low but non-zero probability of exploitation today. The flaw is not yet in the CISA KEV catalog. An attacker can trigger the overflow via the web interface from a remote host, potentially gaining arbitrary code execution on the device.
OpenCVE Enrichment