Impact
The vulnerability is a buffer overflow in the fromSafeMacFilter function of the SafeMacFilter web form. This flaw occurs when the page argument is manipulated, allowing an attacker to overflow the buffer and potentially execute arbitrary code on the device. The overflow can compromise confidentiality, integrity, and availability. The weakness is a classic stack‑based buffer overflow, as indicated by CWE‑119 and CWE‑120.
Affected Systems
Affected devices are Tenda F456 routers running firmware version 1.0.0.5. No other versions are known to be affected from the published data. The vulnerability is located in the web management interface of the router.
Risk and Exploitability
The CVSS score of 8.7 denotes a high severity vulnerability. The EPSS score is below 1%, suggesting a low current exploitation probability, but the presence of a public exploit increases risk. The flaw can be reached remotely by sending a specially crafted request to the SafeMacFilter endpoint, so any device exposed to the Internet is a potential target. The vulnerability is not listed in the CISA KEV catalog, but its exploitability makes it relevant for immediate attention.
OpenCVE Enrichment