Tenda HG3 Stack-Based Buffer Overflow Vulnerability in IPv6 Routing Configuration

Vulnerability

A stack-based buffer overflow vulnerability has been identified in the Tenda HG3 router operating system version 2.0. The issue arises in the 'formUploadConfig' function within the '/boaform/formIPv6Routing' file. The vulnerability is triggered by improper validation of the 'destNet' argument, allowing remote attackers to exploit the flaw. This exploitation can lead to unauthorized access to the device's internal system interfaces and cause denial-of-service conditions, disrupting the normal operation of the affected IoT device.

Impact

Exploitation of this vulnerability causes a stack-based buffer overflow, allowing for potential arbitrary code execution or causing the device to crash and become unresponsive.

Added: Apr 27, 2026, 8:22 PM
Updated: Apr 27, 2026, 8:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.1
exploitability
8.7
remediation
0.0
relevance
6.7
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.