Impact
A stack-based buffer overflow exists in the PPTPUserSetting function of Tenda F453 router firmware 1.0.0.3. By manipulating the delno parameter in the web form /goform/PPTPUserSetting, an attacker can overwrite the stack, potentially hijacking execution flow and achieving remote code execution. The vulnerability stems from unchecked input handling and is related to CWE-119, CWE-121 and CWE-787.
Affected Systems
Tenda F453 routers running firmware 1.0.0.3 are affected. Only this firmware revision is documented as vulnerable. The flaw resides in the httpd component handling PPTP user settings, accessed through the router’s web interface.
Risk and Exploitability
The CVSS score is 8.7, indicating high severity, while the EPSS score is below 1%, suggesting low current exploitation probability. However, publicly available exploits exist, meaning the risk is not negligible. The vulnerability is not listed in the KEV catalog. Attackers can exploit the flaw remotely without authentication via the router’s web interface, potentially executing arbitrary code on the device and compromising network traffic.
OpenCVE Enrichment