CVE-2026-3802Disclosure(tenda / i3)

LOWCVSS 7.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch tenda i3 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was determined in Tenda i3 1.0.0.6(2204). Affected by this issue is the function formexeCommand of the file /goform/exeCommand. Executing a manipulation of the argument cmdinput can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • i3
  • i3_firmware

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 4 mentions (2026-03-09); latest day: 1
  • 8 total mentions across 4 days

Affected systems

Vendors
Products
i3i3_firmware

2 versions affected across 2 products

Deep dive

Activity timeline8 mentions / 4d
01234Mentions · 2026-03-09: 4Mentions · 2026-03-10: 2Mentions · 2026-03-12: 1Mentions · 2026-03-13: 1Patch / Workaround · 2026-03-09: 1Technical Details · 2026-03-09: 4Technical Details · 2026-03-12: 1Technical Details · 2026-03-13: 103-0903-1003-1203-13
Signal classification4 categories
Disclosure
450.0%
General
225.0%
Patch
112.5%
Discl
112.5%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-094
Disclosure2General1Patch1
2026-03-102
Discl1General1
2026-03-121
Disclosure1
2026-03-131
Disclosure1
Full discourse8 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3802 (CVSS:7.4, HIGH) is Analyzed. A vulnerability was determined in Tenda i3 1.0.0.6(2204). Affected by this issue is the function formexeCommand of the f..https://nvd.nist.gov/vuln/detail/CVE-2026-3802 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-3802 as a high‑severity flaw in Tenda i3 firmware, noting the affected function but without providing any exploit, PoC, or mitigation details.

    0000028
    172 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3802 (CVSS:7.4, HIGH) is Analyzed. A vulnerability was determined in Tenda i3 1.0.0.6(2204). Affected by this issue is the function formexeCommand of the f..https://nvd.nist.gov/vuln/detail/CVE-2026-3802 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    A new CVE (CVE-2026-3802) has been disclosed with basic technical details, but no PoC, exploit, or patch information is provided.

    0000032
    172 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-3802 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-3802 #CVE-2026-3802 #CVE #High  #CyberSecurity #InfoSec https://t.co/N5dRdIWkFl

    Post summary

    The tweet merely informs readers of the existence of CVE-2026-3802 with a high severity score, but offers no technical details, PoC, exploit, patch, or evidence of active exploitation.

    0000023
    91 followersView on X
  • RedPacket Security@RedPacketSec
    Discl

    CVE Alert: CVE-2026-3802 - Tenda - i3 - https://www.redpacketsecurity.com/cve-alert-cve-2026-3802-tenda-i3/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-3802 #tenda #i3

    Post summary

    A CVE alert was posted for CVE-2026-3802 affecting Tenda i3, but the post provides no further technical details or actionable information.

    0000059
    3.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3802 A vulnerability was determined in Tenda i3 1.0.0.6(2204). Affected by this issue is the function formexeCommand of the file /goform/exeCommand. Executing a manipulation… https://www.cve.org/CVERecord?id=CVE-2026-3802

    Post summary

    This is an initial disclosure of CVE-2026-3802 affecting the Tenda i3 firmware, highlighting a vulnerability in the formexeCommand function at /goform/exeCommand, but it does not include proof-of-concept code, exploit details, patches, or evidence of active exploitation.

    00000137
    56.6K followersView on X
  • DailyCVE@dailycve
    General

    🔴 Tenda i3, Stack-based Buffer Overflow, #CVE-2026-3802 (Critical) https://dailycve.com/tenda-i3-stack-based-buffer-overflow-cve-2026-3802-critical/

    Post summary

    The post announces a critical stack‑based buffer overflow CVE‑2026‑3802 affecting the Tenda i3, pointing to a DailyCVE article for further details.

    0000030
    166 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-3802: HIGH] Critical vulnerability found in Tenda i3 1.0.0.6(2204) allows remote attackers to execute a stack-based buffer overflow using formexeCommand function in /goform/exeCommand file. Patch rec...#cve,CVE-2026-3802,#cybersecurity https://cvefind.com/CVE-2026-3802

    Post summary

    The text announces a high‑severity stack‑based buffer overflow in Tenda i3 firmware and recommends a patch, without providing PoC, exploit code, or evidence of active exploitation.

    0000065
    600 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3802 - Tenda i3 exeCommand formexeCommand stack-based overflow Intel Report: https://ift.tt/LpnUd7J

    Post summary

    The alert announces the Tenda i3 stack‑based overflow CVE-2026-3802, providing its type but no PoC, exploits, or patches.

    0000034
    347 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendai3---
OStendai3_firmware1.0.0.6\(2204\)--

Explore more