CVE-2026-3971

HIGH

Tenda i3 1.0.0.6(2204) - Buffer Overflow

Title source: llm
STIX 2.1

Description

A vulnerability has been found in Tenda i3 1.0.0.6(2204). Affected by this vulnerability is the function formwrlSSIDset of the file /goform/wifiSSIDset. The manipulation of the argument index/GO leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.

Scores

CVSS v3 8.8
EPSS 0.0010
EPSS Percentile 26.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-119 CWE-121 CWE-787
Status published
Products (2)
Tenda/i3 1.0.0.6(2204)
tenda/i3_firmware 1.0.0.6\(2204\)
Published Mar 12, 2026
Tracked Since Mar 12, 2026