Impact
A stack-based buffer overflow has been identified in the fromRouteStatic function of the /goform/RouteStatic file on Tenda CX12L routers. By manipulating the page argument, an attacker can overflow the stack and potentially execute arbitrary code, giving them full control over the device.
Affected Systems
The flaw affects Tenda CX12L routers running firmware version 16.03.53.12. No other versions or products are currently listed as impacted.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.7, indicating high severity. An exploit is publicly available, and the attack can be performed remotely through the web interface, making it easy for threat actors to target the device. The exception of EPSS data and lack of KEV listing do not diminish the urgency, as remote exploitation is straightforward and could lead to a loss of confidentiality, integrity, and availability of the network.
OpenCVE Enrichment