Impact
This vulnerability is a buffer overflow in the httpd component of the Tenda F456 router, triggered by manipulating the dips argument to the fromGstDhcpSetSer function in /goform/GstDhcpSetSer. The flaw allows an attacker to overwrite memory on remote systems, potentially leading to arbitrary code execution. It is categorized as CWE‑119 and CWE‑120. The CVSS score of 8.7 indicates a high severity impact on confidentiality, integrity, and availability.
Affected Systems
The affected product is the Tenda F456 router running firmware version 1.0.0.5. No other vendor or product versions are listed as impacted in the CVE data.
Risk and Exploitability
The CVSS score of 8.7 denotes a high risk, but the EPSS score of <1% indicates a low probability of widespread exploitation at present. Because the exploit is publicly documented, remote attackers can target the router over the network by sending crafted HTTP requests to the vulnerable endpoint. The vulnerability is not listed in the CISA KEV catalog, however it remains a significant threat if mitigated. The likely attack vector is remote through the router’s web management interface.
OpenCVE Enrichment