Tenda FH451
cpe:2.3:h:tenda:fh451:*:*:*:*:*:*:*, +1 more
- <= 1.0.0.9
A buffer overflow vulnerability has been identified in the Tenda FH451 router, affecting versions through 1.0.0.9. The issue arises in the file '/goform/GstDhcpSetSer', where an unknown input manipulation leads to the overflow. This vulnerability can be exploited remotely, and a public exploit is available.
Exploitation of this vulnerability causes a stack overflow, crashing the router and making it inaccessible. This disruption can be confirmed with Burp Suite, which shows the service is no longer reachable.
The vulnerability can be reproduced by sending a POST request to the '/goform/GstDhcpSetSer' endpoint with a crafted 'dips' parameter that exceeds 32 bytes. This can be done using a proof-of-concept script that automates the request.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.