CVE-2026-3972

HIGH

Tenda W3 1.0.0.3(2204) - Buffer Overflow

Title source: llm

Description

A vulnerability was found in Tenda W3 1.0.0.3(2204). Affected by this issue is the function formSetCfm of the file /goform/setcfm of the component HTTP Handler. The manipulation of the argument funcpara1 results in stack-based buffer overflow. The attack can only be performed from the local network. The exploit has been made public and could be used.

Scores

CVSS v3 8.8
EPSS 0.0003
EPSS Percentile 8.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-121 CWE-119
Status published
Products (1)
Tenda/W3 < 1.0.0.3(2204)
Published Mar 12, 2026
Tracked Since Mar 12, 2026