CVE Details
Basic Information
| Title | Tenda FH451 HTTP POST Request L7Prot frmL7ProtForm stack-based overflow |
|---|---|
| Type | cve |
| Published | 2025-07-12T22:32:07.315Z |
| Modified | 2025-07-12T22:32:07.315Z |
Product Information
| Vendor | Tenda |
|---|---|
| Product | FH451 |
| Version | 1.0.0.9 |
CVSS Information
| Base Score | 8.7 (HIGH) |
|---|---|
| Attack Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P |
AI Analysis
| AI Description | A critical stack-based buffer overflow vulnerability in Tenda FH451 1.0.0.9 allows remote attackers to exploit the HTTP POST request handler via the frmL7ProtForm function. This can lead to system compromise and data breaches. |
|---|---|
| AI Severity | Critical |
| AI Vendor | Tenda |
| AI Product | FH451 |
| AI Version | 1.0.0.9 |
Affected Products
- Tenda FH451 1.0.0.9
Additional Information
| CWE List | CWE-121, CWE-119 |
|---|---|
| Source | VulDB |
Description
A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. Affected is the function frmL7ProtForm of the file /goform/L7Prot of the component HTTP POST Request Handler. The manipulation of the argument page leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.