CVE-2026-3970

8.8

Tenda · i3

A stack-based buffer overflow in the Tenda i3 router allows remote attackers to execute arbitrary code via a crafted index parameter in the /goform/wifiSSIDget function.

Executive summary

A critical stack-based buffer overflow vulnerability in Tenda i3 firmware allows remote code execution, posing a severe risk to device integrity and network security.

Vulnerability

The vulnerability exists within the formwrlSSIDget function of the /goform/wifiSSIDget endpoint. By sending a specially crafted index parameter to this function, an attacker can trigger a stack-based buffer overflow, which may lead to memory corruption and potential remote code execution.

Business impact

Successful exploitation of this vulnerability grants an attacker the ability to execute arbitrary code on the affected router. This level of access could lead to complete device compromise, interception of network traffic, or the use of the device as a pivot point for further attacks within the internal network. Given the CVSS score of 8.8, this flaw represents a high-severity risk that could result in significant operational disruption and data exposure.

Remediation

Immediate Action: Check the Tenda support website for firmware updates addressing this buffer overflow; if no update is available for version 1.0.0.6(2204), restrict access to the device management interface.

Proactive Monitoring: Monitor network traffic for unusual POST requests directed at the /goform/wifiSSIDget endpoint and investigate any unexpected device reboots or service instability.

Compensating Controls: Implement strict firewall rules to ensure that the router management interface is not exposed to the public internet, effectively neutralizing the remote attack vector.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists, as documented in the technical write-up by the researcher on GitHub.

Analyst recommendation

The severity of this remote code execution vulnerability necessitates immediate attention from security administrators. Since a public proof-of-concept is available, the likelihood of weaponization is elevated. Organizations using the Tenda i3 router must prioritize restricting management access and applying manufacturer-provided patches as soon as they are released to prevent potential exploitation.

More Tenda CVEs

Sources

Originally found and disclosed by Svigo (VulDB User), per the CVE Program record.