VYPR
Unrated severityNVD Advisory· Published Dec 20, 2022· Updated Apr 16, 2025

CVE-2022-46530

CVE-2022-46530

Description

Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the mac parameter at /goform/GetParentControlInfo.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Tenda F1203 V2.0.1.6 has a buffer overflow in the HTTP GET request handler for /goform/GetParentControlInfo via the mac parameter.

Vulnerability

A buffer overflow vulnerability exists in Tenda F1203 router firmware version V2.0.1.6. The flaw is in the httpd module when processing a GET request to the /goform/GetParentControlInfo endpoint. The mac parameter is copied into a fixed-size buffer without proper length validation, allowing an attacker to overflow the buffer. This affects the Tenda F1203 V2.0.1.6 [1].

Exploitation

An attacker can exploit this vulnerability by sending a crafted HTTP POST request to the router's web interface at /goform/GetParentControlInfo with an overly long mac parameter. No authentication is required, and the request can be sent from the local network. The proof of concept demonstrates a crash (Denial of Service) by providing a long string of a characters as the mac value [1].

Impact

Successful exploitation leads to a buffer overflow, which in the provided proof of concept causes a Denial of Service (DoS) by crashing the httpd service. If further exploited, this could potentially allow arbitrary code execution with the privileges of the web server, compromising the router's integrity and availability [1].

Mitigation

As of the disclosure date, no official patch has been released by Tenda for this vulnerability. Users should monitor Tenda's support page for firmware updates. If not needed, consider disabling remote management and restricting access to the router's web interface to trusted devices only [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Tenda/F1203description
  • Tenda/F1203llm-fuzzy
    Range: = 2.0.1.6

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.