Impact
This is a buffer overflow (CWE-120) vulnerability in the fromSetCmdlineRun function of the Tenda A18 router firmware. By sending a specially crafted input, a remote attacker can cause the function to write beyond the bounds of a buffer, leading to execution of arbitrary code on the device. The impact is loss of both confidentiality and integrity of the system, as the attacker could gain full control over the router.
Affected Systems
The affected product is the Tenda A18 router, model version 15.13.07.09, produced by Shenzhen Jixiang Tengda Technology Co., Ltd. No other vendors or product versions are listed in the data.
Risk and Exploitability
Based on the description, the vulnerability can be triggered by a remote attacker sending malicious data to the router’s command interface—most likely via its web UI or telnet/SSH access. The CVSS score of 9.8 highlights its severity, while the EPSS score of <1% indicates the prevalence of exploitation is low but not negligible. The vulnerability is not listed in CISA KEV, indicating it may not yet have known active exploitation. Nevertheless, a successful buffer overflow would give the attacker control over the firmware, permitting full administrative takeover of the device.
OpenCVE Enrichment