VYPR
Unrated severityNVD Advisory· Published Dec 20, 2022· Updated Apr 16, 2025

CVE-2022-46537

CVE-2022-46537

Description

Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the security parameter at /goform/WifiBasicSet.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A buffer overflow in Tenda F1203 V2.0.1.6 via the security parameter in /goform/WifiBasicSet allows denial of service.

Vulnerability

A buffer overflow vulnerability exists in the httpd module of Tenda F1203 router firmware version V2.0.1.6. The flaw is triggered when processing a crafted HTTP POST request to the /goform/WifiBasicSet endpoint, specifically via an overly long security parameter. The affected firmware is available from Tenda's official download page [1].

Exploitation

An attacker can exploit this vulnerability by sending a specially crafted HTTP POST request to the vulnerable endpoint. The provided proof-of-concept (PoC) demonstrates sending a request with a security parameter containing approximately 4000 'a' characters. No authentication is explicitly required in the PoC, though the example includes a cookie with user=admin; the vulnerability may be reachable without prior authentication [1].

Impact

Successful exploitation causes a denial of service (DoS) condition, likely crashing the httpd process and rendering the router's web interface unavailable. The reference notes that the PoC results in a DoS; no remote code execution or data exfiltration is described [1].

Mitigation

As of the publication date (2022-12-20), no patched firmware version has been released by Tenda. Users are advised to monitor Tenda's support page for updates. If the device is no longer supported, replacement with a supported model is recommended. No workarounds are documented [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Tenda/F1203description
  • Tenda/F1203llm-fuzzy
    Range: = V2.0.1.6

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.