Impact
The vulnerability is a stack overflow triggered by a crafted wl_radio parameter within the formwrlSSIDset function of the Tenda W3 Wireless Router firmware. This flaw allows an attacker to corrupt the call stack, leading to a forced reboot and consequently a denial‑of‑service condition. The weakness is classified as CWE-121, representing a stack‑based buffer overflow.
Affected Systems
Devices affected are Shenzhen Tenda Technology Co., Ltd. Tenda W3 Wireless Routers running firmware version 1.0.0.3(2204). No other product or version details are documented.
Risk and Exploitability
The CVSS score of 7.5 places this issue in the high severity range. The EPSS score is not available, and the vulnerability has not yet appeared in the CISA KEV catalog. Because the flaw is exposed through a web‑based configuration interface, it can likely be exploited remotely by sending a specially crafted request to the router over an exposed management network. A successful attack would result in repeated reboots, interrupting network services and availability.
OpenCVE Enrichment