Description
A security flaw has been discovered in Tenda W3 1.0.0.3(2204). This issue affects the function formWifiMacFilterGet of the file /goform/WifiMacFilterGet of the component POST Parameter Handler. Performing a manipulation of the argument wl_radio results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks.
Published: 2026-03-12
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution via stack-based buffer overflow
Action: Immediate Patch
AI Analysis

Impact

A stack-based buffer overflow occurs in the formWifiMacFilterGet function of Tenda W3’s /goform/WifiMacFilterGet endpoint when the wl_radio argument is manipulated. This vulnerability, identified as CWE-119, CWE-121, and CWE-787, allows a remote attacker to overwrite stack data and potentially execute arbitrary code on the router.

Affected Systems

The affected device is the Tenda W3 router running firmware version 1.0.0.3(2204). No other vendors or products are listed as affected.

Risk and Exploitability

The CVSS score is 8.7 and the EPSS score is less than 1%, indicating a high severity but currently low probability of widespread exploitation. The issue is publicly known and the exploit code has been released, enabling remote attackers to target the device via HTTP POST requests to /goform/WifiMacFilterGet. The vulnerability is not yet catalogued in the CISA KEV list.

Generated by OpenCVE AI on April 2, 2026 at 23:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the Tenda support site for a firmware update that addresses the buffer overflow.
  • If an updated firmware is available, install it immediately.
  • If no update is available, restrict external access to the router’s administrative interface.
  • Change the default administrative username and password.
  • Consider isolating the router on a separate network segment or applying firewall rules to block remote POST requests to /goform/WifiMacFilterGet.

Generated by OpenCVE AI on April 2, 2026 at 23:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Tenda w3 Firmware
Weaknesses CWE-787
CPEs cpe:2.3:h:tenda:w3:-:*:*:*:*:*:*:*
cpe:2.3:o:tenda:w3_firmware:1.0.0.3\(2204\):*:*:*:*:*:*:*
Vendors & Products Tenda w3 Firmware

Fri, 13 Mar 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Tenda
Tenda w3
Vendors & Products Tenda
Tenda w3

Thu, 12 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 12 Mar 2026 03:00:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in Tenda W3 1.0.0.3(2204). This issue affects the function formWifiMacFilterGet of the file /goform/WifiMacFilterGet of the component POST Parameter Handler. Performing a manipulation of the argument wl_radio results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks.
Title Tenda W3 POST Parameter WifiMacFilterGet formWifiMacFilterGet stack-based overflow
Weaknesses CWE-119
CWE-121
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-03-12T14:44:15.372Z

Reserved: 2026-03-11T14:01:27.580Z

Link: CVE-2026-3975

cve-icon Vulnrichment

Updated: 2026-03-12T14:44:04.132Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-12T03:15:58.523

Modified: 2026-04-02T20:07:35.820

Link: CVE-2026-3975

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-03T09:39:33Z

Weaknesses