Executive brief
The Tenda O3 wireless router, used for long-range outdoor wireless networking, contains a security flaw in its web management interface. By sending a specially crafted web request, an attacker can crash the device's management service. This results in a denial-of-service, preventing administrators from managing the device and potentially disrupting network connectivity.
Technical details
A stack-based buffer overflow exists in the 'fromNetToolGet' CGI handler of the Tenda O3 router. The vulnerability is located in the 'fromNetToolGet' function, where the 'ip' HTTP parameter is retrieved using 'websGetVar' and subsequently copied into a fixed-size stack buffer ('acStack_12cc') using the unsafe 'strcpy' function without length validation. An unauthenticated remote attacker can exploit this by sending a crafted HTTP request with an oversized 'ip' string. Successful exploitation leads to a process crash or device instability, resulting in a Denial of Service (DoS). The vulnerability was identified in firmware version v1.0.0.5(4180).
Affected products
- Tenda O3 Wireless Router v1.0.0.5(4180)
Timeline
- 2026-03-13: other: CVE request submitted to MITRE
- 2026-06-06: disclosed: Public disclosure
- 2026-06-09: advisory: NVD publication date