Impact
A stack-based buffer overflow exists in the /goform/SetSysTimeCfg POST handler on Tenda AC7 routers. By sending a crafted Time field, an attacker can overwrite the stack, potentially leading to arbitrary code execution or denial of service. The flaw is cataloged as CWE-119 and CWE-121, indicating a memory corruption vulnerability that can compromise router integrity.
Affected Systems
The vulnerability impacts Tenda AC7 devices running firmware version 15.03.06.44. The affected component is the SetSysTime configuration endpoint exposed over the router’s web interface. Any AC7 unit with this firmware is considered vulnerable until a patched release is applied.
Risk and Exploitability
The CVSS score of 8.7 classifies this issue as high severity. Exploitation is possible remotely without authentication, and publicly available exploits have already been disclosed. Although EPSS data is missing and the vulnerability is not yet listed in KEV, the combination of remote access, lack of authentication, and memory corruption creates a significant threat landscape for exposed routers.
OpenCVE Enrichment