CVE-2026-3976: Tenda w3 Firmware

High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.

A weakness has been identified in Tenda W3 1.0.0.3(2204). Impacted is the function formWifiMacFilterSet of the file /goform/WifiMacFilterSet of the component POST Parameter Handler. Executing a manipulation of the argument index/GO can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.

Affected products

  • Tenda w3 Firmware: version 1.0.0.3(2204) only

Published 2026-03-12. Last modified 2026-06-17.