Impact
A buffer overflow exists in the formWanRedirect function of Tenda HG10’s Boa Web Server, allowing attackers to manipulate the ‘if’ argument and inject arbitrary data. This flaw, categorized as CWE-119 and CWE-120, can be exploited remotely to potentially execute arbitrary code, resulting in loss of confidentiality, integrity, and availability for the affected device.
Affected Systems
The vulnerability affects Tenda HG10 firmware version 300001138, targeting the Boa Web Server component and specifically the /boaform/formWanRedirect endpoint. Devices running this firmware are thus at risk.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, however the exploit is publicly disclosed and can be launched remotely. Attackers with network access to the device could trigger the buffer overflow and gain control of the router.
OpenCVE Enrichment