Executive brief
The Tenda F3 wireless router is affected by a security vulnerability that could allow an attacker to disrupt the device's operations. By sending specially crafted data to the router's Wi-Fi configuration settings, an attacker could cause the system to crash or behave unpredictably. This could lead to a loss of internet connectivity for users and potentially allow for unauthorized access to limited device information.
Technical details
A classic buffer overflow (CWE-120) exists in the Tenda F3 router firmware versions V12.01.01.48_multi and subsequent releases. The vulnerability is located in the 'goform/setWifi' endpoint and is triggered by providing an overly long string to the 'wifiTimeClose' parameter. An attacker can exploit this over a network, though the attack complexity is rated as high, likely due to specific configuration requirements or timing constraints. Successful exploitation can lead to a denial-of-service condition or potentially limited information disclosure. As of the advisory date, the referenced GitHub proof-of-concept link is reported as broken, and official patches should be sought from the vendor.
Affected products
- Tenda F3 V12.01.01.48_multi and later
Timeline
- 2025-09-10: advisory: Initial NVD publication date
- 2026-07-04: other: Last modified date in NVD record