Impact
The vulnerability is a buffer overflow in the Tenda W20E router firmware version 16.01.0.6(2782). The flaw enables an attacker to execute arbitrary code on the device, potentially compromising its confidentiality, integrity, and availability, and allowing further exploitation of the network the router serves.
Affected Systems
Tenda W20E wireless router running firmware version 16.01.0.6(2782). The vulnerability is an incomplete fix for earlier issues, but only this specific build is affected.
Risk and Exploitability
The CVE description reports a CVSS score of 9.8, and the EPSS score is < 1%. The vulnerability is not listed in the CISA KEV catalog. The low EPSS score suggests a small chance of exploitation, but the high CVSS score indicates that if exploited, the impact would be severe, allowing an attacker to execute arbitrary code. Based on the description, the likely attack vector is network traffic that can reach the router’s management or data plane pathways, though explicit details are missing.
OpenCVE Enrichment