CVE-2026-2187General(tenda / rx3)

LOWCVSS 7.4 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was found in Tenda RX3 16.03.13.11. The affected element is the function set_qosMib_list of the file /goform/formSetQosBand. Performing a manipulation of the argument list results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made public and could be used.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • rx3
  • rx3_firmware

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
rx3rx3_firmware

2 versions affected across 2 products

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-02-08: 3Technical Details · 2026-02-08: 202-08
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-2187 A vulnerability was found in Tenda RX3 16.03.13.11. The affected element is the function set_qosMib_list of the file /goform/formSetQosBand. Performing a manipulation o… https://www.cve.org/CVERecord?id=CVE-2026-2187

    Post summary

    The text announces CVE-2026-2187 affecting the Tenda RX3 router, identifies the vulnerable function, but provides no proof‑of‑concept, exploit, or patch details.

    00010228
    56.5K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-2187: HIGH] Stack-based buffer overflow vulnerability discovered in Tenda RX3 16.03.13.11 allows remote attacks via manipulation of arguments in set_qosMib_list function of /goform/formSetQosBand fil...#cve,CVE-2026-2187,#cybersecurity https://cvefind.com/CVE-2026-2187

    Post summary

    The tweet announces a high‑severity stack‑based buffer overflow in Tenda RX3 firmware that could allow remote attackers to manipulate QoS parameters; no PoC, exploit code, patch, or active exploitation is reported.

    0000070
    583 followersView on X
  • VulDB 🛡@vuldb
    General

    We have just added an important vulnerability affecting Tenda RX3 (CVE-2026-2187) https://vuldb.com/?id.344890

    Post summary

    A new vulnerability (CVE-2026-2187) affecting the Tenda RX3 has been added to a vulnerability database, but no further details are provided.

    0000070
    2.1K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendarx3---
OStendarx3_firmware16.03.13.11--

Explore more