Impact
A stack-based buffer overflow exists in the frmL7ImForm function located in /goform/L7Im of the Tenda F451 firmware. By manipulating the page parameter, an attacker can overflow the buffer on the stack and potentially execute arbitrary code. The vulnerability is remotely exploitable through the web interface, and public exploits have been disclosed. The high CVSS score of 8.7 reflects the severity of remote code execution risk.
Affected Systems
Devices affected are Tenda F451 routers running firmware version 1.0.0.7_cn_svn7958. The vulnerability is tied specifically to the frmL7ImForm handler on the web interface of that firmware build.
Risk and Exploitability
The CVSS base score of 8.7 indicates high criticality, while the EPSS score is unavailable and the vulnerability is not listed in CISA's KEV catalog. The attack vector is remote, exploiting a web interface; no network or local privilege prerequisites are required, making it readily exploitable from any internet-connected device that can reach the router's management interface. Without timely patching, an attacker could gain full control of the device.
OpenCVE Enrichment