Impact
The vulnerable component is the formQuickIndex function in the httpd module of the Tenda F456 router. By manipulating the mit_linktype parameter, an attacker can trigger a buffer overflow, potentially allowing execution of arbitrary code on the device. This can compromise the confidentiality, integrity, and availability of the router and the network it serves.
Affected Systems
Affected hardware is the Tenda F456 router running firmware version 1.0.0.5. The vulnerability is exposed through the router’s web interface at the /goform/QuickIndex endpoint, and can be accessed by clients on the network or externally if the interface is reachable.
Risk and Exploitability
The CVSS score of 8.7 classifies this flaw as high severity. Although its EPSS score is below 1%, the vulnerability is already publicly exploited and can be triggered remotely via HTTP requests, with no authentication required. The lack of inclusion in the CISA KEV catalog does not mitigate the risk; active exploitation remains possible for any device running the vulnerable firmware.
OpenCVE Enrichment