Impact
A buffer overflow flaw is present in the frmL7ProtForm handler of the /goform/L7Prot endpoint in the httpd component of Tenda F456 firmware 1.0.0.5. The vulnerability is triggered when a specially crafted message is sent to the "page" argument, causing an uncontrolled write beyond the bounds of the buffer in memory. The overflow can lead to execution of arbitrary code on the device, giving a remote attacker control of the router.
Affected Systems
The flaw affects the Tenda F456 router running firmware version 1.0.0.5. No other version numbers are specified in the data, so only this configuration is confirmed to be vulnerable.
Risk and Exploitability
The flaw scores a high CVSS of 8.7, indicating serious impact. The EPSS indicates an exploitation probability of less than 1 percent, and the vulnerability is not listed in the CISA KEV catalog. Remote exploitation can be achieved via HTTP requests to the affected endpoint, and the public release of an exploit demonstrates that attackers could mount successful attacks if the router is exposed to the Internet.
OpenCVE Enrichment