CVE-2026-3804Disclosure(tenda / i3)

LOWCVSS 7.4 · HIGH

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Prioritize remediation for tenda i3 systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A security flaw has been discovered in Tenda i3 1.0.0.6(2204). This vulnerability affects the function formWifiMacFilterSet of the file /goform/WifiMacFilterSet. The manipulation of the argument index results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • i3
  • i3_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • 10 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 8 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 5 mentions (2026-03-09); latest day: 1
  • 10 total mentions across 5 days

Affected systems

Vendors
Products
i3i3_firmware

2 versions affected across 2 products

Deep dive

Activity timeline10 mentions / 5d
01345Mentions · 2026-03-08: 1Mentions · 2026-03-09: 5Mentions · 2026-03-10: 2Mentions · 2026-03-12: 1Mentions · 2026-03-13: 1Active Exploitation · 2026-03-09: 1Technical Details · 2026-03-09: 3Technical Details · 2026-03-12: 1Technical Details · 2026-03-13: 103-0803-0903-1003-1203-13
Signal classification3 categories
Disclosure
880.0%
Active Exploitation
110.0%
General
110.0%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-03-081
Disclosure1
2026-03-095
Active Exploitation1Disclosure4
2026-03-102
Disclosure2
2026-03-121
Disclosure1
2026-03-131
General1
Full discourse10 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3804 Tenda i3 Remote Stack-Based Buffer Overflow in Wi-Fi MAC Filter Configuration https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3804

    Post summary

    The notice announces CVE-2026-3804, a stack‑based buffer overflow affecting the Tenda i3 Wi‑Fi MAC filter configuration, with no further details on PoC, mitigation, or active exploitation.

    0101088
    4.0K followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-3804 (CVSS:7.4, HIGH) is Analyzed. A security flaw has been discovered in Tenda i3 1.0.0.6(2204). This vulnerability affects the function formWifiMacFilter..https://nvd.nist.gov/vuln/detail/CVE-2026-3804 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post references CVE-2026-3804, noting its CVSS score and the affected function in Tenda i3, but does not provide evidence of exploitation, PoCs, patches, or a debunking claim.

    0000033
    172 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3804 (CVSS:7.4, HIGH) is Analyzed. A security flaw has been discovered in Tenda i3 1.0.0.6(2204). This vulnerability affects the function formWifiMacFilter..https://nvd.nist.gov/vuln/detail/CVE-2026-3804 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet announces and briefly describes CVE-2026-3804, a high‑severity flaw in Tenda i3 affecting the formWifiMacFilter function, with a CVSS rating of 7.4 and a link to the NVD entry.

    0000027
    172 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-3804 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-3804 #CVE-2026-3804 #CVE #High  #CyberSecurity #InfoSec https://t.co/UcOrYR3zuo

    Post summary

    The tweet announces CVE‑2026‑3804, stating its severity (8.8) and high risk level, with a link to the NVD entry, but does not provide any PoC, exploit, active exploitation, patch, technical details, or false‑positive claim.

    0000024
    91 followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-3804 - Tenda - i3 - https://www.redpacketsecurity.com/cve-alert-cve-2026-3804-tenda-i3/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-3804 #tenda #i3

    Post summary

    An alert for CVE‑2026‑3804 affecting Tenda i3 devices is announced with a reference to an external security blog post.

    0000066
    3.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3804 A security flaw has been discovered in Tenda i3 1.0.0.6(2204). This vulnerability affects the function formWifiMacFilterSet of the file /goform/WifiMacFilterSet. The ma… https://www.cve.org/CVERecord?id=CVE-2026-3804

    Post summary

    The post announces the discovery of CVE-2026-3804 in Tenda i3 firmware, noting the affected function but providing no further technical or exploit details.

    00000128
    56.6K followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    A lot of offensive activities were identified targeting Tenda i3 (CVE-2026-3804) https://vuldb.com/?ctiid.349771

    Post summary

    The tweet reports that CVE-2026-3804 on Tenda i3 is being actively exploited in offensive operations, but no PoC, exploit code, patch, or technical details are included.

    0000071
    2.1K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3804 - Tenda i3 WifiMacFilterSet formWifiMacFilterSet stack-based overflow Intel Report: https://ift.tt/rmuV1z4

    Post summary

    The post discloses CVE‑2026‑3804, a stack‑based overflow in Tenda i3 WifiMacFilterSet, and shares a link to an intel report; it contains no PoC, exploit code, patch, or evidence of active exploitation.

    0000034
    347 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-3804: HIGH] Security flaw in Tenda i3 1.0.0.6(2204) allows remote attackers to exploit a stack-based buffer overflow through /goform/WifiMacFilterSet, exposing systems to risk.#cve,CVE-2026-3804,#cybersecurity https://cvefind.com/CVE-2026-3804

    Post summary

    The tweet announces a high‑severity stack-based buffer overflow in Tenda i3 firmware (1.0.0.6), exposing systems to remote exploitation via /goform/WifiMacFilterSet. No PoC, exploit, patch, or active exploitation details are provided.

    0000065
    600 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    There is a new vulnerability with elevated criticality in Tenda i3 (CVE-2026-3804) https://vuldb.com/?id.349771

    Post summary

    The post announces a newly identified critical vulnerability (CVE-2026-3804) affecting the Tenda i3 device.

    00000111
    2.1K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendai3---
OStendai3_firmware1.0.0.6\(2204\)--

Explore more