CVE-2026-3975
HIGHTenda W3 1.0.0.3(2204) - Buffer Overflow
Title source: llmDescription
A security flaw has been discovered in Tenda W3 1.0.0.3(2204). This issue affects the function formWifiMacFilterGet of the file /goform/WifiMacFilterGet of the component POST Parameter Handler. Performing a manipulation of the argument wl_radio results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks.
References (5)
Scores
CVSS v3
8.8
EPSS
0.0009
EPSS Percentile
25.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-119
CWE-121
CWE-787
Status
published
Products (2)
Tenda/W3
1.0.0.3(2204)
tenda/w3_firmware
1.0.0.3\(2204\)
Published
Mar 12, 2026
Tracked Since
Mar 12, 2026