Tenda WH450 Stack-Based Buffer Overflow Vulnerability in Wireless Restart HTTP Request Handler

Vulnerability

A stack-based buffer overflow vulnerability has been identified in the Tenda WH450 router, specifically in the firmware version 1.0.0.18. The issue arises within the HTTP request handler for the '/goform/wirelessRestart' endpoint. This vulnerability can be exploited remotely by unauthenticated attackers, potentially leading to arbitrary code execution or causing a denial-of-service condition. The buffer overflow is triggered by manipulating the 'GO' parameter with excessively long input, allowing attackers to overwrite the stack and disrupt normal execution flow.

Impact

Exploitation of this vulnerability allows for a stack-based buffer overflow, which could be leveraged to execute arbitrary code or cause a denial-of-service condition on the affected device.

Reproduction

The vulnerability can be reproduced by sending a GET request to the '/goform/wirelessRestart' endpoint with the 'GO' parameter containing a payload longer than 42 bytes. This can be done using a script that automates the process, such as one written in Python that uses the 'requests' library to send the payload.

Added: Dec 18, 2025, 5:16 PM
Updated: Dec 18, 2025, 5:16 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
8.7
remediation
0.0
relevance
1.4
threat
6.4
urgency
2.9
incentive
5.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.