CVE-2026-3976

HIGH

Tenda W3 1.0.0.3(2204) - Buffer Overflow

Title source: llm

Description

A weakness has been identified in Tenda W3 1.0.0.3(2204). Impacted is the function formWifiMacFilterSet of the file /goform/WifiMacFilterSet of the component POST Parameter Handler. Executing a manipulation of the argument index/GO can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.

Scores

CVSS v3 8.8
EPSS 0.0009
EPSS Percentile 25.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-121 CWE-119
Status published
Products (1)
Tenda/W3 < 1.0.0.3(2204)
Published Mar 12, 2026
Tracked Since Mar 12, 2026