Impact
A firmware flaw in the Tenda FH1202 router, version 1.2.0.14(408), allows a malicious client to send a specially crafted HTTP request to the /goform/WrlExtraSet endpoint. The Go parameter passed to the WrlExtraSet function is not properly validated, causing a stack-based buffer overflow (CWE-119 and CWE-121). An attacker can trigger this bug remotely, potentially executing arbitrary code on the device and compromising its confidentiality, integrity, and availability.
Affected Systems
The vulnerability is identified for the Tenda FH1202 router running firmware 1.2.0.14(408). No other firmware versions or additional products are listed as affected in the available data.
Risk and Exploitability
The flaw carries a CVSS score of 8.7, indicating high severity. The EPSS score is less than 1%, suggesting a low current exploitation probability, and the vulnerability is not yet catalogued in the CISA KEV list. Nevertheless, a publicly available exploit demonstrates that an attacker can automate the overflow, which makes the risk significant for devices that expose the web management interface to the internet.
OpenCVE Enrichment