Tenda O3V2 Stack-Based Buffer Overflow Vulnerability

Vulnerability

A critical stack-based buffer overflow vulnerability has been identified in the Tenda O3V2 router, specifically in the 1.0.0.12(3880) firmware version. The issue arises in the httpd component, within the formWifiMacFilterSet function of the /goform/setWrlFilterList file. The vulnerability can be exploited remotely by manipulating the macList argument, leading to potential arbitrary code execution.

Impact

Exploitation of this vulnerability causes a stack-based buffer overflow, which can lead to arbitrary code execution on the device.

Reproduction

The vulnerability can be reproduced by sending a crafted request to the /goform/setWrlFilterList endpoint, including an overly long macList parameter. This excessive length causes a stack-based buffer overflow, which can be exploited to execute arbitrary code.

Added: Jul 11, 2025, 1:28 AM
Updated: Jul 11, 2025, 1:28 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
8.7
remediation
0.0
relevance
0.3
threat
6.4
urgency
2.9
incentive
5.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.