Impact
A stack‑based buffer overflow exists in the formIPMacBindAdd function of the HTTP Handler in Tenda W20E firmware version 15.11.0.61068_1546_841_CN_TDC. The flaw is triggered by manipulating the IPMacBindRule argument with a maliciously crafted value. Attackers can send a POST request over HTTP to trigger the overflow, potentially compromising the device’s integrity and creating opportunities for further exploitation.
Affected Systems
The vulnerability affects the Tenda W20E router running firmware 15.11.0.61068_1546_841_CN_TDC. No other firmware versions or products are listed as affected.
Risk and Exploitability
The CVSS base score is 7.1, indicating high severity, and the EPSS score is less than 1%, suggesting that attacks are infrequent at present. The vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the stack overflow remotely via the HTTP formIPMacBindAdd endpoint, which could lead to integrity violations or potential code execution, although the CVE description does not confirm arbitrary code execution.
OpenCVE Enrichment