Impact
A stack‑based buffer overflow exists in the fromNatlimit function of the /goform/Natlimit endpoint on Tenda F453 routers. When an attacker manipulates the 'page' argument, the overflow corrupts the stack and can be leveraged to execute arbitrary code or seize full control of the device. The flaw is classified as CWE‑119 and CWE‑121.
Affected Systems
The vulnerability affects the Tenda F453 router running firmware version 1.0.0.3. It is specific to the Parameters Handler component on this model; no other firmware revisions are listed as impacted.
Risk and Exploitability
The CVSS score of 8.7 signals high severity, while the EPSS score of less than 1% indicates a low probability of widespread attacks, yet a publicly available exploit is known. The flaw is not listed in the CISA KEV catalog. The likely attack vector is remote, via the router’s web interface, where an attacker crafts a malicious HTTP request to /goform/Natlimit to trigger the overflow. Access to the router and exposure of its management interface are prerequisites for exploitation.
OpenCVE Enrichment