CVE-2026-1329
8.8Tenda · AX1803
Tenda AX1803 version 1.0.0.1 contains a stack-based buffer overflow vulnerability in the fromGetWifiGuestBasic function, allowing remote attackers to trigger memory corruption.
Executive summary
A critical stack-based buffer overflow vulnerability in the Tenda AX1803 router allows remote attackers to trigger memory corruption, posing a severe risk to device integrity.
Vulnerability
The vulnerability exists in the fromGetWifiGuestBasic function within the /goform/WifiGuestSet endpoint, where improper handling of specific arguments leads to a stack-based buffer overflow. The attack can be launched remotely by an authenticated user.
Business impact
The exploitation of this vulnerability can result in full system compromise, as memory corruption often facilitates arbitrary code execution. Given the CVSS score of 8.8, this flaw represents a high-severity risk that could lead to unauthorized network control, data interception, or the complete denial of service for connected environments.
Remediation
Immediate Action: Since a vendor-supplied patch is currently unknown, administrators should restrict access to the web management interface to trusted networks only and disable the guest network feature if it is not required.
Proactive Monitoring: Monitor device logs for unusual traffic patterns directed at the /goform/WifiGuestSet endpoint and investigate any unexpected device reboots or service instability.
Compensating Controls: Implement a Web Application Firewall (WAF) or network-level access control list (ACL) to block unauthorized or anomalous HTTP requests directed at the vulnerable management interface.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the researcher write-up provided in the technical references.
Analyst recommendation
Due to the high severity of this buffer overflow, organizations must prioritize the isolation of affected Tenda AX1803 devices from the public internet. Until an official firmware update is released by Tenda, ensure that administrative access is strictly controlled and that all management interfaces are inaccessible from external networks to prevent remote exploitation.
More Tenda CVEs
Sources
Originally found and disclosed by wlupus (VulDB User), per the CVE Program record.
- VDB-342305 | Tenda AX1803 WifiGuestSet fromGetWifiGuestBasic stack-based overflow Vulnerability database entry
- VDB-342305 | CTI Indicators (IOB, IOC, IOA)
- Submit #736063 | Tenda AX1803 V1.0.0.1 Stack-based Buffer Overflow Third-party advisory
- Submit #736064 | Tenda AX1803 V1.0.0.1 Stack-based Buffer Overflow (Duplicate) Third-party advisory
- Submit #736065 | Tenda AX1803 V1.0.0.1 Stack-based Buffer Overflow (Duplicate) Third-party advisory
- Submit #736066 | Tenda AX1803 V1.0.0.1 Stack-based Buffer Overflow (Duplicate) Third-party advisory
- Submit #736067 | Tenda AX1803 V1.0.0.1 Stack-based Buffer Overflow (Duplicate) Third-party advisory
- Exploit / PoC