Junglewise Threat Intelligence

CVE-2026-36772: Tenda W3 Wireless Router stack overflow in formwrlSSIDget

CVE-2026-36772 · Severity: info · CVSS 7.5 · Published 2026-06-09

Technologies: Tenda W3 Wireless Router. Vendors: Tenda.

Executive brief

The Tenda W3 is a wireless router used for home and small office networking. A security flaw in the router's web management interface allows an attacker to send a specially crafted request that crashes the device. This results in a denial-of-service, cutting off internet access for all connected users until the device is manually restarted.

Technical details

A stack-based buffer overflow exists in the Tenda W3 Wireless Router v1.0.0.3(2204) within the 'formwrlSSIDget' CGI handler. The vulnerability is located in the 'formwrlSSIDget' function where user-controlled input from the 'index' parameter is passed to 'sprintf' without length validation to construct a configuration key. While the 'wl_radio' parameter must be set to '0' to reach the vulnerable branch, the 'index' parameter can be manipulated to overflow the 'local_c14' stack buffer. An unauthenticated attacker can exploit this over the network via a crafted HTTP request to cause a crash or reboot (Denial of Service), and potentially achieve arbitrary code execution.

Affected products

  • Tenda W3 Wireless Router v1.0.0.3(2204)

Timeline

  • 2026-03-04: other: CVE request submitted to MITRE
  • 2026-06-06: disclosed: Public disclosure
  • 2026-06-09: advisory: NVD published date

References

Related threats