Executive brief
The Tenda F3 is a wireless router used for home and small office networking. A security flaw in its parental control settings allows an attacker to send specially crafted data that can crash the device or potentially allow unauthorized code execution. This could lead to a loss of internet connectivity or a compromise of the router's security.
Technical details
A classic buffer overflow (CWE-120) exists in the Tenda F3 router firmware versions V12.01.01.48_multi and subsequent releases. The vulnerability is located within the 'goform/setParentControl' endpoint and is triggered by providing an overly long string to the 'onlineList' parameter. An unauthenticated attacker can exploit this over a network, though the attack complexity is rated as high, likely due to specific environmental or configuration requirements. Successful exploitation can lead to a denial-of-service (DoS) condition or potentially remote code execution (RCE).
Affected products
- Tenda F3 V12.01.01.48_multi and later
Timeline
- 2025-09-10: disclosed
- 2025-09-10: advisory