Impact
A stack-based buffer overflow occurs in the formWifiMacFilterGet function of Tenda W3’s /goform/WifiMacFilterGet endpoint when the wl_radio argument is manipulated. This vulnerability, identified as CWE-119, CWE-121, and CWE-787, allows a remote attacker to overwrite stack data and potentially execute arbitrary code on the router.
Affected Systems
The affected device is the Tenda W3 router running firmware version 1.0.0.3(2204). No other vendors or products are listed as affected.
Risk and Exploitability
The CVSS score is 8.7 and the EPSS score is less than 1%, indicating a high severity but currently low probability of widespread exploitation. The issue is publicly known and the exploit code has been released, enabling remote attackers to target the device via HTTP POST requests to /goform/WifiMacFilterGet. The vulnerability is not yet catalogued in the CISA KEV list.
OpenCVE Enrichment