Impact
A buffer overflow flaw exists in the SafeEmailFilter function of Tenda F456 firmware. By manipulating the argument "page" sent to /goform/SafeEmailFilter, an attacker can overflow the buffer and potentially execute arbitrary code on the device. The vulnerability is remote‑only, meaning it can be triggered by an external network connection, and exploitation code has already been published, raising the risk of real‑world attacks.
Affected Systems
Users running Tenda F456 firmware version 1.0.0.5 are affected. The issue originates in the SafeEmailFilter component exposed through the web interface; no other Tenda products or firmware versions are known to be impacted.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity classified as a high‑lateral‑impact remote code execution. The EPSS score of less than 1% suggests a low probability of widespread exploitation at present, and the vulnerability has not yet entered CISA’s KEV catalog. The description confirms the attack vector is remote via the web interface, and the existence of published exploit code indicates that motivated adversaries could use this flaw without additional constraints.
OpenCVE Enrichment