Description
Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain a stack overflow in the wl_radio parameter of the formwrlSSIDget function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published: 2026-06-09
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A stack overflow has been identified in the wl_radio parameter of the formwrlSSIDget function on the Tenda W3 Wireless Router. The flaw allows an attacker to supply specially crafted input that overflows the stack, causing the operating process to crash and leading to a denial of service. The vulnerability does not provide remote code execution or data exfiltration capabilities; its primary impact is service interruption. The weakness corresponds to classic buffer overrun issues, typically classified under buffer copy errors or out‑of‑bounds writes.

Affected Systems

Shenzhen Tenda Technology Co., Ltd. provides the Tenda W3 Wireless Router with firmware version 1.0.0.3(2204). This specific firmware build is susceptible to the stack overflow described, and no other products or versions are listed as affected.

Risk and Exploitability

The CVSS score is 6.5 and the EPSS score is <1%. The likely attack vector is through network interaction with the router’s management interface, given that the vulnerable function is accessed via HTTP. Because the vulnerability is not listed in CISA’s KEV catalog, no widespread commercial exploit has been reported; however, the lack of a patched version makes the risk moderate for networks where the router is exposed to untrusted traffic.

Generated by OpenCVE AI on June 10, 2026 at 22:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for firmware updates from Shenzhen Tenda and update the router to a patched version as soon as available.
  • Configure network segmentation to restrict access to the router’s management interface from external or untrusted networks.
  • Implement input validation or rate‑limiting on the router’s management interface to mitigate malformed wl_radio requests, if supported by the device.

Generated by OpenCVE AI on June 10, 2026 at 22:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 10 Jun 2026 22:30:00 +0000

Type Values Removed Values Added
Title Tenda W3 Wireless Router Stack Overflow Leading to Denial of Service

Wed, 10 Jun 2026 20:15:00 +0000

Type Values Removed Values Added
Title Stack Overflow in Tenda W3 Wireless Router Causing Denial of Service
Weaknesses CWE-120
CWE-787

Wed, 10 Jun 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 10 Jun 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-121
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Wed, 10 Jun 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Tenda
Tenda w3 Wireless Router
Vendors & Products Tenda
Tenda w3 Wireless Router

Tue, 09 Jun 2026 22:15:00 +0000

Type Values Removed Values Added
Title Stack Overflow in Tenda W3 Wireless Router Causing Denial of Service
Weaknesses CWE-120
CWE-787

Tue, 09 Jun 2026 18:45:00 +0000

Type Values Removed Values Added
Description Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain a stack overflow in the wl_radio parameter of the formwrlSSIDget function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
References

Subscriptions

Tenda W3 Wireless Router
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-06-10T17:29:47.543Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-36772

cve-icon Vulnrichment

Updated: 2026-06-10T17:29:40.711Z

cve-icon NVD

Status : Deferred

Published: 2026-06-09T19:17:43.727

Modified: 2026-06-10T18:16:44.453

Link: CVE-2026-36772

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-10T22:15:18Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow