Impact
A command injection vulnerability exists in the FromWriteFacMac routine of the httpd component on Tenda F456 routers. By crafting a malicious value for the mac argument in the /goform/WriteFacMac endpoint, an attacker can execute arbitrary shell commands on the device. The vulnerability permits remote exploitation and has been publicly exposed.
Affected Systems
The affected product is the Tenda F456 router with firmware version 1.0.0.5. No other Tenda firmware revisions are explicitly listed as vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, but the fact that the flaw allows remote command injection raises the risk of full device compromise. The EPSS score of <1% suggests that exploitation is relatively likely compared to other vulnerabilities. The flaw is not included in the CISA KEV catalog, yet the public availability of exploits means attackers could target these routers, especially if exposed to the Internet.
OpenCVE Enrichment