CVE-2026-2187

8.8

Tenda · RX3

A stack-based buffer overflow in the set_qosMib_list function of Tenda RX3 version 16.03.13.11 allows for remote code execution via manipulation of the list argument.

Executive summary

A remote, stack-based buffer overflow vulnerability in Tenda RX3 routers poses a critical risk of full system compromise.

Vulnerability

This vulnerability is a stack-based buffer overflow located in the set_qosMib_list function within the /goform/formSetQosBand file. The flaw can be triggered by an authenticated attacker by manipulating the list argument, leading to memory corruption.

Business impact

The exploitation of this vulnerability allows for unauthorized remote control of the affected networking hardware. Given the CVSS score of 8.8, successful execution could result in complete loss of confidentiality, integrity, and availability for the device, potentially allowing an attacker to pivot into the internal network or intercept sensitive traffic.

Remediation

Immediate Action: Since no specific patch is currently identified, administrators should restrict management access to the router to trusted internal IP addresses only and disable remote administration features.

Proactive Monitoring: Security teams should monitor device logs for unexpected crashes, memory errors, or unusual POST requests directed at the /goform/formSetQosBand endpoint.

Compensating Controls: Deploy firewall rules to block unauthorized traffic from reaching the router management interface, effectively reducing the attack surface for remote exploitation attempts.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept is available via the technical write-up referenced in the GitHub issue linked by the CVE record.

Analyst recommendation

Due to the presence of a public proof-of-concept and the high severity of the memory corruption flaw, this issue presents a significant risk to organizational infrastructure. Administrators must immediately isolate the management interface of affected Tenda RX3 units from the public internet and continue to monitor vendor communication channels for an official firmware patch.

More Tenda CVEs

Sources

Originally found and disclosed by LX-66-LX (VulDB User), per the CVE Program record.