Impact
A buffer overflow flaw exists in the httpd component of Tenda F456 firmware 1.0.0.5. The vulnerability is triggered by manipulating the "page" argument in the fromSetIpBind function that can be accessed remotely through the /goform/SetIpBind endpoint. The overflow may allow an attacker to corrupt memory and potentially execute arbitrary code on the device, which is why the flaw is classified under CWE‑119 and CWE‑120.
Affected Systems
The affected system is the Tenda F456 router operating on firmware version 1.0.0.5. No other Tenda models or firmware releases are listed as impacted.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity, while the EPSS score of less than 1% suggests a low probability of exploitation at the time of this assessment. The vulnerability is not listed in CISA’s KEV catalog. An attacker can launch the exploit remotely by sending a specially crafted request to the vulnerable httpd endpoint; public exploit code has already been released.
OpenCVE Enrichment