CVE-2026-3976
HIGHTenda W3 1.0.0.3(2204) - Buffer Overflow
Title source: llmDescription
A weakness has been identified in Tenda W3 1.0.0.3(2204). Impacted is the function formWifiMacFilterSet of the file /goform/WifiMacFilterSet of the component POST Parameter Handler. Executing a manipulation of the argument index/GO can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.
References (7)
Scores
CVSS v3
8.8
EPSS
0.0009
EPSS Percentile
25.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-121
CWE-119
Status
published
Products (1)
Tenda/W3
< 1.0.0.3(2204)
Published
Mar 12, 2026
Tracked Since
Mar 12, 2026