CVE-2026-2187
8.8Tenda · RX3
A stack-based buffer overflow in the set_qosMib_list function of Tenda RX3 version 16.03.13.11 allows for remote code execution via manipulation of the list argument.
Executive summary
A remote, stack-based buffer overflow vulnerability in Tenda RX3 routers poses a critical risk of full system compromise.
Vulnerability
This vulnerability is a stack-based buffer overflow located in the set_qosMib_list function within the /goform/formSetQosBand file. The flaw can be triggered by an authenticated attacker by manipulating the list argument, leading to memory corruption.
Business impact
The exploitation of this vulnerability allows for unauthorized remote control of the affected networking hardware. Given the CVSS score of 8.8, successful execution could result in complete loss of confidentiality, integrity, and availability for the device, potentially allowing an attacker to pivot into the internal network or intercept sensitive traffic.
Remediation
Immediate Action: Since no specific patch is currently identified, administrators should restrict management access to the router to trusted internal IP addresses only and disable remote administration features.
Proactive Monitoring: Security teams should monitor device logs for unexpected crashes, memory errors, or unusual POST requests directed at the /goform/formSetQosBand endpoint.
Compensating Controls: Deploy firewall rules to block unauthorized traffic from reaching the router management interface, effectively reducing the attack surface for remote exploitation attempts.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept is available via the technical write-up referenced in the GitHub issue linked by the CVE record.
Analyst recommendation
Due to the presence of a public proof-of-concept and the high severity of the memory corruption flaw, this issue presents a significant risk to organizational infrastructure. Administrators must immediately isolate the management interface of affected Tenda RX3 units from the public internet and continue to monitor vendor communication channels for an official firmware patch.
More Tenda CVEs
Sources
Originally found and disclosed by LX-66-LX (VulDB User), per the CVE Program record.
- VDB-344890 | Tenda RX3 formSetQosBand set_qosMib_list stack-based overflow Vulnerability database entry
- VDB-344890 | CTI Indicators (IOB, IOC, IOA)
- Submit #749721 | Tenda RX3 V16.03.13.11 Stack-based Buffer Overflow Third-party advisory
- Exploit / PoC
- tenda.com.cn