PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-36778 Shenzhen Tenda Technology Co., Ltd CVE debrief

A stack overflow vulnerability was discovered in the Tenda O3 Wireless Router v1.0.0.5(4180). The vulnerability exists in the username parameter of the R7WebsSecurityHandler function, allowing attackers to cause a Denial of Service (DoS) via a crafted HTTP request. This CVE has a CVSS score of 4.9 and a severity rating of MEDIUM.

Vendor
Shenzhen Tenda Technology Co., Ltd
Product
Tenda O3 Wireless Router
CVSS
MEDIUM 4.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-09
Original CVE updated
2026-06-10
Advisory published
2026-06-09
Advisory updated
2026-06-10

Who should care

Administrators and users of the Tenda O3 Wireless Router v1.0.0.5(4180) should be aware of this vulnerability and take steps to mitigate it.

Technical summary

The CVE-2026-36778 vulnerability is a stack overflow in the username parameter of the R7WebsSecurityHandler function in the Tenda O3 Wireless Router v1.0.0.5(4180). This allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

Defensive priority

MEDIUM

Recommended defensive actions

  • Update to the latest firmware version if available.
  • Limit access to the router's web interface to trusted IP addresses.
  • Monitor for suspicious HTTP requests to the router.

Evidence notes

The CVE-2026-36778 vulnerability was discovered and reported by an unknown source. The CVE record and NVD detail pages provide additional information about this vulnerability.

Official resources

CVE-2026-36778 was published on 2026-06-09T19:17:44.090Z and modified on 2026-06-10T18:16:44.987Z.