CVE-2026-2181Disclosure(tenda / rx3)

LOWCVSS 7.4 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A security flaw has been discovered in Tenda RX3 16.03.13.11. Affected by this vulnerability is an unknown functionality of the file /goform/openSchedWifi. Performing a manipulation of the argument schedStartTime/schedEndTime results in stack-based buffer overflow. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • rx3
  • rx3_firmware

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Exploit: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
rx3rx3_firmware

2 versions affected across 2 products

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-09: 2PoC Mentioned / Linked · 2026-02-09: 1Technical Details · 2026-02-09: 102-09
Signal classification2 categories
Disclosure
150.0%
Exploit
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVEFind.com@CveFindCom
    Exploit

    [CVE-2026-2181: HIGH] Critical security flaw found in Tenda RX3 16.03.13.11 allows remote stack-based buffer overflow via /goform/openSchedWifi, could lead to cyber attacks. Exploit now public.#cve,CVE-2026-2181,#cybersecurity https://cvefind.com/CVE-2026-2181

    Post summary

    The post announces a high‑severity stack‑buffer overflow in Tenda RX3, notes that an exploit is now publicly available, but does not mention any patch, active exploitation, or PoC details.

    0000080
    583 followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-2181 - Tenda - RX3 - https://www.redpacketsecurity.com/cve-alert-cve-2026-2181-tenda-rx3/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-2181 #tenda #rx3

    Post summary

    The text announces a CVE-2026-2181 vulnerability affecting the Tenda RX3 and directs readers to an external security alert page for further details.

    0000082
    3.5K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendarx3---
OStendarx3_firmware16.03.13.11--

Explore more