Impact
A stack‑based buffer overflow occurs in the form_fast_setting_wifi_set function of the /goform/fast_setting_wifi_set interface. This flaw allows a remote attacker to send crafted data to the device and overwrite control data on the stack, potentially enabling arbitrary code execution. The vulnerability is classified as CWE‑119 and CWE‑121.
Affected Systems
The Tenda A18 Pro model, specifically firmware version 02.03.02.28, is affected. No other versions or products are listed as impacted.
Risk and Exploitability
The CVSS score is 8.7, indicating high severity. EPSS information is not available, and the vulnerability is not listed in CISA’s KEV catalog. The flaw is exploitable remotely and a public exploit has already been disclosed, making the risk of exploitation significant for devices running the affected firmware.
OpenCVE Enrichment