Executive brief
The Tenda W3 wireless router, used for home and small office networking, contains a security flaw in its web management interface. An attacker can send a specially crafted web request to the device to cause it to crash or reboot. This results in a denial of service, disrupting internet connectivity for all connected users.
Technical details
A stack-based buffer overflow exists in the R7WebsSecurityHandler function of the Tenda W3 router (firmware v1.0.0.3(2204)). The vulnerability is triggered when the 'username' and 'password' parameters are retrieved via websGetVar without length validation. Specifically, the 'username' parameter is subsequently passed to a strcpy() call, which copies the user-controlled string into a fixed-size stack buffer (aiStack_238). An unauthenticated attacker can exploit this by sending a crafted HTTP request with an overly long username string, leading to a crash (Denial of Service) or potentially arbitrary code execution. The vulnerability is reachable via the default web handler defined in the main execution flow.
Affected products
- Tenda W3 Wireless Router v1.0.0.3(2204)
Timeline
- 2026-03-15: other: CVE request submitted to MITRE
- 2026-06-06: disclosed: Public disclosure
- 2026-06-09: advisory: NVD published date