Junglewise Threat Intelligence

CVE-2026-36778: Tenda O3 Wireless Router stack overflow in R7WebsSecurityHandler

CVE-2026-36778 · Severity: info · CVSS 7.5 · Published 2026-06-09

Technologies: Tenda O3 Wireless Router. Vendors: Tenda.

Executive brief

The Tenda O3 is a wireless router used for long-range outdoor networking. A security flaw in how the device handles login requests allows an attacker to send a specially crafted web request that crashes the device. This results in a denial-of-service, cutting off network connectivity for users and potentially requiring a manual reboot to restore operations.

Technical details

A stack-based buffer overflow exists in the R7WebsSecurityHandler function of the Tenda O3 router (firmware v1.0.0.5). The vulnerability is located in the CGI handler where the 'username' and 'password' parameters are retrieved via websGetVar without length validation. Specifically, the 'username' input is passed to an unbounded strcpy call into a fixed-size stack buffer (aiStack_238). An unauthenticated remote attacker can exploit this by sending a crafted HTTP request with an overly long username string, leading to a device crash (Denial of Service) or potentially arbitrary code execution. The vulnerability is reachable via the default web interface.

Affected products

  • Tenda O3 Wireless Router v1.0.0.5(4180)

Timeline

  • 2026-03-10: other: CVE request submitted to MITRE
  • 2026-06-06: disclosed: Public disclosure
  • 2026-06-09: advisory: NVD published date

References

Related threats