Impact
A vulnerability exists in the UploadCfg function of the Tenda A15 router firmware 15.13.07.13. The function improperly handles the File argument, leading to a stack-based buffer overflow that can be triggered remotely. This flaw corresponds to CWE-119 and CWE-121 and can allow an attacker to execute arbitrary code on the device, potentially taking full control of the router. The description confirms the overflow is exploitable from outside the local network and that an exploit has already been disclosed to the public.
Affected Systems
The issue affects the Tenda A15 wireless router running firmware version 15.13.07.13. The Common Platform Enumeration identifies the hardware as tenda:a15 and the firmware as tenda:a15_firmware:15.13.07.13. No other versions are listed, so the risk is specific to this build.
Risk and Exploitability
The CVSS score of 9.3 places this flaw in the Critical severity range. While the EPSS indicates a low probability of exploitation (less than 1%), the vulnerability is publicly disclosed and can be harnessed from remote clients. It is not present in the CISA Known Exploited Vulnerabilities catalog. Because the flaw resides in a remote-accessible CGI interface, a threat actor with external network reach could launch the attack without requiring prior login credentials. The high severity and publicly available exploit code mean a rapid response is warranted.
OpenCVE Enrichment