Junglewise Threat Intelligence

CVE-2026-5567: Tenda M3 buffer overflow in setAdvPolicyData

CVE-2026-5567 · Severity: high · CVSS 8.8 · Published 2026-04-05

Vendors: Tenda.

Executive brief

A security vulnerability has been identified in the Tenda M3 Access Controller, a device used to manage wireless networks. An attacker can exploit this flaw to cause the device to crash or stop responding, leading to a denial of service. In some cases, this could allow for further unauthorized access or disruption of the managed network infrastructure.

Technical details

A stack-based buffer overflow exists in the 'setAdvPolicyData' function of Tenda M3 firmware version 1.0.0.10, specifically within the 'sub_648D4' subroutine. The vulnerability is caused by an unsafe 'strncpy' operation where the length parameter is calculated from the position of a colon character in the user-controlled 'rebootTime' parameter without validating the destination buffer size. A remote attacker with low privileges can exploit this by sending a specially crafted POST request to '/goform/setAdvPolicyData'. Successful exploitation can lead to a crash of the web management service, device-wide denial of service (DoS), or potential remote code execution. A public exploit (PoC) is available.

Affected products

  • Tenda M3 Access Controller 1.0.0.10

Timeline

  • 2026-03-19: disclosed: Vulnerability details and PoC published on GitHub by researcher Moxxkidd.
  • 2026-04-05: advisory: CVE-2026-5567 published.

References