Impact
The vulnerability resides in the formGstDhcpSetSer function of the /goform/GstDhcpSetSerof web interface on Tenda F1202 routers. By sending a specially crafted argument named dips, an attacker can overflow the stack and overwrite return addresses, enabling the execution of arbitrary code on the device. This flaw composes a classic buffer overflow (CWE‑119) coupled with stack‑based control‑flow hijacking (CWE‑121), giving the attacker full control over the router.
Affected Systems
Affected devices are Tenda F1202 routers running firmware version 1.2.0.20(408). No other firmware revisions are referenced in the advisory. The back‑end of the affected function is exposed via the web interface, so any router with this firmware is vulnerable.
Risk and Exploitability
The CVSS score is 8.7, indicating a high impact vulnerability. The EPSS score is not available, but the issue has been publicly disclosed, and exploit code is available, meaning the practical risk is elevated. The flaw can be leveraged remotely over the HTTP interface without authentication, making it accessible to unauthenticated attackers who can reach the device from the local network or, in some cases, the internet if the router is exposed. Despite not being listed in the CISA KEV catalog, the combination of high CVSS, remote attack vector, and available exploit warrants immediate attention.
OpenCVE Enrichment