Impact
The vulnerability is a stack‑based buffer overflow in the formWrlExtraSet function of the Tenda FH1201 router firmware. By sending a crafted GO parameter to the /goform/WrlExtraSet endpoint, an attacker can overflow the stack and potentially execute arbitrary code. The flaw is an instance of the CWE‑119 (Buffer Overflow) and CWE‑121 (Stack-based Buffer Overflow) weaknesses. If exploited, the attacker could gain complete control over the device, compromising confidentiality, integrity and availability.
Affected Systems
The affected device is the Tenda FH1201 residential router running firmware version 1.2.0.14(408). Vim is present in the firmware of all units distributed with this version of firmware, including those whose CPE identifiers match cpe:2.3:o:tenda:fh1201_firmware:1.2.0.14(408).* . Users of older or later firmware revisions are not listed as affected, so the impact is limited to the specified revision.
Risk and Exploitability
The CVSS base score of 8.7 denotes a high severity, and the risk is compounded by the fact that the attack can be performed from remote without authentication. The EPSS score is below 1 %, indicating that widespread exploitation is currently unlikely, yet the published exploit and the availability of a publicly‑accessible endpoint mean that a determined adversary could still target vulnerable routers. The vulnerability is not recorded in the CISA KEV catalog, but its exploitation potential warrants proactive remediation.
OpenCVE Enrichment