CVE-2026-3973
HIGHTenda W3 1.0.0.3(2204) - Buffer Overflow
Title source: llmDescription
A vulnerability was determined in Tenda W3 1.0.0.3(2204). This affects the function formSetAutoPing of the file /goform/setAutoPing of the component POST Parameter Handler. This manipulation of the argument ping1/ping2 causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
References (7)
Scores
CVSS v3
8.8
EPSS
0.0009
EPSS Percentile
25.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-121
CWE-119
Status
published
Products (1)
Tenda/W3
< 1.0.0.3(2204)
Published
Mar 12, 2026
Tracked Since
Mar 12, 2026