Impact
A stack-based buffer overflow exists in the fromAddressNat function of Tenda CX12L firmware 16.03.53.12. By manipulating the page argument, an attacker can overwrite memory on the stack, potentially enabling arbitrary code execution on the device. The flaw is triggered through a remote request, and the public exploit raises the risk of a full system compromise. The vulnerability is classified as CWE‑119 and CWE‑121.
Affected Systems
The affected product is the Tenda CX12L wireless router running firmware version 16.03.53.12. No other versions are explicitly listed; users of this specific build are at risk.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity, and the lack of an EPSS rating does not diminish the fact that the exploit is publicly available and can be triggered remotely. While the vulnerability is not currently in the CISA KEV catalog, its remote nature and confirmed exploit code make it a likely target for adversaries. The high score, remote attack vector, and public exploit suggest that the risk is significant and should be addressed promptly.
OpenCVE Enrichment