Executive brief
The Tenda W3 wireless router, used for home and small office networking, contains a security flaw in its web management interface. An attacker can send a specially crafted web request to the device to cause it to crash or reboot. This results in a denial of service, disrupting internet connectivity for all connected users.
Technical details
A stack-based buffer overflow exists in the 'ask_to_reboot' function of the Tenda W3 router firmware v1.0.0.3(2204). The vulnerability is triggered when the 'GO' HTTP parameter, retrieved via 'websGetVar', is passed to the 'ask_to_reboot' function and subsequently processed by an unbounded 'sprintf' call: 'sprintf(buf, "reboot.asp?page=%s", param_2)'. An attacker can provide an excessively long string in the 'GO' parameter to overflow the fixed-size stack buffer. This can lead to a crash of the 'httpd' process or a full device reboot, resulting in a Denial of Service. While the primary impact is DoS, arbitrary code execution may be possible depending on the presence of exploit mitigations like stack canaries or ASLR.
Affected products
- Tenda (Shenzhen Tenda Technology) W3 Wireless Router v1.0.0.3(2204)
Timeline
- 2026-03-04: other: CVE request submitted to MITRE
- 2026-06-06: disclosed: Public disclosure via GitHub repository
- 2026-06-09: advisory: NVD published date