CVE-2026-2185

8.8

Tenda · RX3

A stack-based buffer overflow in the Tenda RX3 MAC filtering configuration endpoint allows remote attackers to trigger memory corruption via the devName or mac arguments.

Executive summary

A critical stack-based buffer overflow vulnerability in Tenda RX3 firmware enables remote attackers to compromise system integrity.

Vulnerability

This vulnerability involves a stack-based buffer overflow within the set_device_name function in the /goform/setBlackRule component. The flaw is triggered by improper input validation of the devName or mac parameters, which can be exploited by an authenticated user to achieve memory corruption.

Business impact

The vulnerability carries a CVSS score of 8.8, indicating a high risk of total system impact. Successful exploitation could lead to unauthorized code execution or service disruption, potentially resulting in complete loss of control over the affected networking device, leading to network instability or unauthorized access to internal traffic.

Remediation

Immediate Action: Since no specific patch is currently available, administrators should immediately restrict access to the device management interface to trusted IP addresses only.

Proactive Monitoring: Monitor device logs for unusual traffic patterns targeting the /goform/setBlackRule endpoint and watch for unexpected device reboots which may indicate crash attempts.

Compensating Controls: Implement a strict firewall policy to prevent untrusted network segments from reaching the device management interface.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists as documented in the linked GitHub research issue.

Analyst recommendation

Given the high severity of this memory corruption flaw and the availability of a public proof-of-concept, users must treat this as a priority. Restrict administrative access to the Tenda RX3 management interface immediately to mitigate the risk of remote exploitation while awaiting further guidance or firmware updates from the vendor.

More Tenda CVEs

Sources

Originally found and disclosed by LX-66-LX (VulDB User), per the CVE Program record.