Impact
The vulnerability in the Tenda F453 firmware version 1.0.0.3 allows an attacker to inject arbitrary shell commands via the mac argument to the /goform/WriteFacMac form. This results in remote code execution on the device, enabling full control over the affected device. The weakness is related to command injection weaknesses listed as CWE‑74, CWE‑77, and CWE‑78.
Affected Systems
Vendors and products affected are the Tenda F453 wireless router. The specific firmware identified as vulnerable is version 1.0.0.3.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, while the EPSS score of 3% suggests a low probability of exploitation at present. The vulnerability has not been listed in CISA’s KEV catalog, but public exploit code is available. The attack vector is inferred to be remote, as the payload can be delivered over the network via the router’s web interface, making it potentially reachable from external or compromised internal hosts.
OpenCVE Enrichment