Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.4

Tenda W3 Router Allows Remote Attackers to Crash the Device

CVE-2026-4007
Summary

A weakness in the Tenda W3 router's POST data handling can be exploited remotely, allowing attackers to crash the device. This could lead to a denial of service for users. To mitigate this, update the router to the latest version or consider replacing it with a more secure device.

Original title
A vulnerability was detected in Tenda W3 1.0.0.3(2204). This vulnerability affects unknown code of the file /goform/wifiSSIDget of the component POST Parameter Handler. Performing a manipulation of...
Original description
A vulnerability was detected in Tenda W3 1.0.0.3(2204). This vulnerability affects unknown code of the file /goform/wifiSSIDget of the component POST Parameter Handler. Performing a manipulation of the argument index results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit is now public and may be used.
nvd CVSS2.0 9.0
nvd CVSS3.1 8.8
nvd CVSS4.0 7.4
Vulnerability type
CWE-119 Buffer Overflow
CWE-121 Stack-based Buffer Overflow
Published: 12 Mar 2026 · Updated: 14 Mar 2026 · First seen: 12 Mar 2026