Impact
A stack overflow has been identified in the wl_radio parameter of the formwrlSSIDget function on the Tenda W3 Wireless Router. The flaw allows an attacker to supply specially crafted input that overflows the stack, causing the operating process to crash and leading to a denial of service. The vulnerability does not provide remote code execution or data exfiltration capabilities; its primary impact is service interruption. The weakness corresponds to classic buffer overrun issues, typically classified under buffer copy errors or out‑of‑bounds writes.
Affected Systems
Shenzhen Tenda Technology Co., Ltd. provides the Tenda W3 Wireless Router with firmware version 1.0.0.3(2204). This specific firmware build is susceptible to the stack overflow described, and no other products or versions are listed as affected.
Risk and Exploitability
The CVSS score is 6.5 and the EPSS score is <1%. The likely attack vector is through network interaction with the router’s management interface, given that the vulnerable function is accessed via HTTP. Because the vulnerability is not listed in CISA’s KEV catalog, no widespread commercial exploit has been reported; however, the lack of a patched version makes the risk moderate for networks where the router is exposed to untrusted traffic.
OpenCVE Enrichment