CVE-2026-2181

8.8

Tenda · RX3

A stack-based buffer overflow in the Tenda RX3 router allows remote attackers to trigger memory corruption via the /goform/openSchedWifi endpoint.

Executive summary

A critical stack-based buffer overflow in Tenda RX3 routers exposes devices to remote code execution and system compromise.

Vulnerability

This vulnerability is a stack-based buffer overflow occurring within the /goform/openSchedWifi file. An attacker with low privileges can trigger this memory corruption by manipulating the schedStartTime or schedEndTime arguments, potentially leading to arbitrary code execution.

Business impact

Successful exploitation of this vulnerability could lead to a complete compromise of the affected network device. Given the CVSS score of 8.8, this poses a high risk to business operations, as attackers could gain unauthorized control over network traffic, intercept sensitive data, or use the router as a pivot point for further lateral movement within the internal network.

Remediation

Immediate Action: As no official patch is currently identified, administrators should restrict access to the web management interface and disable the affected scheduling functionality if it is not required for business operations.

Proactive Monitoring: Monitor network traffic for unusual requests directed at the /goform/openSchedWifi endpoint and review device system logs for signs of process crashes or unexpected reboots.

Compensating Controls: Deploy a Web Application Firewall (WAF) or an Intrusion Prevention System (IPS) rule to inspect and block malformed payloads targeting the schedStartTime and schedEndTime parameters.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists as documented in the research write-up at https://github.com/LX-66-LX/cve-new/issues/5.

Analyst recommendation

Due to the high severity of this vulnerability and the availability of public exploit material, immediate defensive action is required. Organizations using Tenda RX3 units should isolate these devices from external access and monitor vendor communication channels closely for the release of an official firmware update to remediate the buffer overflow.

More Tenda CVEs

Sources

Originally found and disclosed by LX-66-LX (VulDB User), per the CVE Program record.