CVE-2026-7151
8.8Tenda · HG3
A stack-based buffer overflow in the Tenda HG3 function formUploadConfig allows remote attackers to trigger memory corruption via the destNet argument.
Executive summary
A critical stack-based buffer overflow vulnerability in Tenda HG3 routers enables remote attackers to execute unauthorized commands or cause system instability.
Vulnerability
The vulnerability exists in the formUploadConfig function within the /boaform/formIPv6Routing file. An attacker with low-level privileges can trigger a stack-based buffer overflow by sending a specially crafted request to the destNet argument.
Business impact
Successful exploitation of this buffer overflow can result in complete system compromise or denial of service for the affected router. Given the CVSS score of 8.8, this vulnerability poses a significant risk to network availability and data integrity, potentially allowing attackers to intercept traffic or gain persistent access to the local network infrastructure.
Remediation
Immediate Action: Contact Tenda support or monitor their official security portal for firmware releases addressing this overflow, as no official patch is currently identified.
Proactive Monitoring: Review firewall and access logs for suspicious traffic directed at the /boaform/formIPv6Routing endpoint, specifically monitoring for unusually long strings within the destNet parameter.
Compensating Controls: Implement strict network segmentation and restrict access to the device management interface to trusted internal IP addresses only.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists as referenced in the technical write-up at the provided Notion documentation link.
Analyst recommendation
The severity of this memory corruption vulnerability necessitates immediate attention. Organizations utilizing Tenda HG3 hardware should isolate affected devices from external network exposure until a vendor-supplied firmware update is available and applied.
More Tenda CVEs
Sources
Originally found and disclosed by 2er00ne (VulDB User), per the CVE Program record.