Executive brief
The Tenda F3 router, a device used to provide wireless internet connectivity in homes and small offices, is affected by a security vulnerability in its web management interface. An attacker could exploit this flaw to cause the device to crash or potentially execute unauthorized commands by sending specially crafted data to the network settings page. This could lead to a loss of internet connectivity or unauthorized access to the router's internal functions.
Technical details
A classic buffer overflow (CWE-120) exists in the Tenda F3 router firmware starting with version V12.01.01.48_multi. The vulnerability is located in the '/goform/setNAT' endpoint, where the 'portList' parameter is processed without adequate bounds checking. An unauthenticated attacker on the network can trigger this overflow by sending a crafted HTTP request. While the attack complexity is rated as high, a successful exploit could lead to a denial-of-service (DoS) condition or potentially remote code execution (RCE). As of the advisory date, users should check for firmware updates from the vendor to mitigate this risk.
Affected products
- Tenda F3 Firmware V12.01.01.48_multi and later
Timeline
- 2025-09-10: disclosed
- 2025-09-10: advisory