CVE-2026-3976

A weakness has been identified in Tenda W3 1.0.0.3(2204). Impacted is the function formWifiMacFilterSet of the file /goform/WifiMacFilterSet of the component POST Parameter Handler. Executing a manipulation of the argument index/GO can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.
Configurations

No configuration.

History

12 Mar 2026, 21:07

Type Values Removed Values Added
Summary
  • (es) Una debilidad ha sido identificada en Tenda W3 1.0.0.3(2204). Afectada está la función formWifiMacFilterSet del archivo /goform/WifiMacFilterSet del componente Gestor de Parámetros POST. Ejecutar una manipulación del argumento index/GO puede llevar a un desbordamiento de búfer basado en pila. Es posible lanzar el ataque de forma remota. El exploit ha sido puesto a disposición del público y podría ser usado para ataques.

12 Mar 2026, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-12 03:15

Updated : 2026-03-12 21:07


NVD link : CVE-2026-3976

Mitre link : CVE-2026-3976

CVE.ORG link : CVE-2026-3976


JSON object : View

Products Affected

No product.

CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-121

Stack-based Buffer Overflow