Impact
A buffer overflow flaw exists in the fromaddressNat handler of the Tenda F456 router, specifically the /goform/addressNat endpoint. By supplying a crafted menufacturer/Go argument, an attacker can overflow internal buffers, potentially overwriting return addresses and executing arbitrary code. The vulnerability is exploitable from outside the local network, allowing an attacker to compromise the router without local access.
Affected Systems
This defect affects the Tenda F456 model running firmware version 1.0.0.5. No other vendor or product variants are listed as vulnerable in the official CNA data.
Risk and Exploitability
The CVSS score of 8.7 indicates high impact, and the EPSS score of less than 1% suggests low likelihood of existing widespread exploitation at present; however, the flaw is publicly documented and a proof‑of‑concept is available. Because the vulnerability is remotely exploitable and can lead to arbitrary code execution, a successful attack would give an adversary full control over the device. The flaw is not yet listed in CISA’s KEV catalog, but its severity warrants immediate attention.
OpenCVE Enrichment