CVE-2026-3801Disclosure(tenda / i3)

LOWCVSS 7.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch tenda i3 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was found in Tenda i3 1.0.0.6(2204). Affected by this vulnerability is the function formSetAutoPing of the file /goform/setAutoPing. Performing a manipulation of the argument ping1/ping2 results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been made public and could be used.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • i3
  • i3_firmware

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 8 classified signals
  • Peaked 3d ago at 4 mentions (2026-03-09); latest day: 1
  • 8 total mentions across 4 days

Affected systems

Vendors
Products
i3i3_firmware

2 versions affected across 2 products

Deep dive

Activity timeline8 mentions / 4d
01234Mentions · 2026-03-09: 4Mentions · 2026-03-10: 2Mentions · 2026-03-12: 1Mentions · 2026-03-13: 1Patch / Workaround · 2026-03-09: 1Technical Details · 2026-03-09: 4Technical Details · 2026-03-10: 1Technical Details · 2026-03-12: 1Technical Details · 2026-03-13: 103-0903-1003-1203-13
Signal classification1 categories
Disclosure
8100.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-094
Disclosure4
2026-03-102
Disclosure2
2026-03-121
Disclosure1
2026-03-131
Disclosure1
Full discourse8 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-3801 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-3801 #CVE-2026-3801 #CVE #High  #CyberSecurity #InfoSec https://t.co/P7aIKTydPP

    Post summary

    The tweet announces CVE-2026-3801 with a high CVSS score of 8.8, references the NVD entry, but provides no PoC, exploit details, or evidence of active attacks.

    0001023
    91 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3801 Tenda i3 Router Remote Stack-Based Buffer Overflow in Ping Configuration https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3801

    Post summary

    The post announces CVE-2026-3801, a stack-based buffer overflow in Tenda i3 router ping configuration, without providing PoC, exploitation, or patch information.

    0001071
    4.0K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3801 (CVSS:7.4, HIGH) is Analyzed. A vulnerability was found in Tenda i3 1.0.0.6(2204). Affected by this vulnerability is the function formSetAutoPing of t..https://nvd.nist.gov/vuln/detail/CVE-2026-3801 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-3801, noting its CVSS score (7.4) and the affected Tenda i3 device's formSetAutoPing function, but does not provide any proof of concept, exploit code, or patch details.

    0000028
    172 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3801 (CVSS:7.4, HIGH) is Analyzed. A vulnerability was found in Tenda i3 1.0.0.6(2204). Affected by this vulnerability is the function formSetAutoPing of t..https://nvd.nist.gov/vuln/detail/CVE-2026-3801 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post highlights discovery of CVE-2026-3801 in Tenda i3 firmware, including its CVSS score and the impacted function, but offers no additional exploitation or mitigation details.

    0000027
    172 followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-3801 - Tenda - i3 - https://www.redpacketsecurity.com/cve-alert-cve-2026-3801-tenda-i3/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-3801 #tenda #i3

    Post summary

    The message announces CVE-2026-3801 for Tenda i3 devices, providing a link to a CVE alert page but no further technical details, PoC, exploit code, or patch information.

    0000057
    3.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3801 A vulnerability was found in Tenda i3 1.0.0.6(2204). Affected by this vulnerability is the function formSetAutoPing of the file /goform/setAutoPing. Performing a manipu… https://www.cve.org/CVERecord?id=CVE-2026-3801

    Post summary

    A new vulnerability (CVE-2026-3801) was disclosed for Tenda i3 firmware 1.0.0.6(2204), affecting the formSetAutoPing function in /goform/setAutoPing; no PoC, exploit, patch, or active exploitation details are included.

    00000136
    56.6K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3801 - Tenda i3 setAutoPing formSetAutoPing stack-based overflow Intel Report: https://ift.tt/wCHE52o

    Post summary

    An alert announces CVE-2026-3801 as a stack‑based overflow in Tenda i3’s setAutoPing, without indicating proof‑of‑concept, exploitation activity, or mitigation information.

    0000038
    347 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-3801: HIGH] Critical buffer overflow vulnerability discovered in Tenda i3 1.0.0.6(2204). Attacker can exploit formSetAutoPing function, triggering a stack-based overflow remotely. Patch recommended.#cve,CVE-2026-3801,#cybersecurity https://cvefind.com/CVE-2026-3801

    Post summary

    The post announces a high‑severity buffer overflow in Tenda i3 that can be triggered remotely via formSetAutoPing and recommends applying a patch.

    0000068
    600 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendai3---
OStendai3_firmware1.0.0.6\(2204\)--

Explore more