Impact
The Tenda F456 router firmware 1.0.0.5 contains a buffer overflow flaw in the fromNatlimitof function of the httpd component. An attacker could send a crafted request over the network to the /goform/Natlimit interface, causing the function to write beyond the bounds of a stack buffer. The description indicates that exploitation may be possible and an exploit has already been published. The specific downstream effect is not explicitly stated in the CVE data.
Affected Systems
The Tenda F456 router with firmware version 1.0.0.5 is the only product listed as impacted in the CNA data.
Risk and Exploitability
The CVSS score of 8.7 classifies this flaw as high severity, and the EPSS score of less than 1% indicates a low likelihood of automated exploitation at the moment. However, the vulnerability is publicly documented and an exploit has already been released, meaning that a skilled attacker could target vulnerable devices. The flaw is not yet listed in the CISA KEV catalog, but that does not diminish the potential for exploitation via remote HTTP traffic.
OpenCVE Enrichment