Impact
A stack-based buffer overflow exists in the HTTP server component of Tenda F451 firmware 1.0.0.7. The flaw is triggered in the fromSafeMacFilter function when an attacker manipulates the page/menufacturer argument sent to /goform/SafeMacFilter. Successful exploitation can lead to arbitrary code execution on the device. The weakness corresponds to CWE-119 (buffer overflow) and CWE-121 (stack-based buffer overflow).
Affected Systems
Devices running Tenda F451 firmware 1.0.0.7 are affected; this version is the only one mentioned for the vulnerability.
Risk and Exploitability
The CVSS score is 8.7, indicating a high severity. No EPSS score is provided, but the exploit has been publicly disclosed and remains available for use. It is not listed in the CISA KEV catalog, yet the remote nature of the attack and public availability of exploit code elevate its risk. An attacker can reach the vulnerable interface over the network and exploit it from anywhere, potentially gaining full control over the device.
OpenCVE Enrichment