CVE-2026-3971Disclosure(tenda / i3)

LOWCVSS 7.4 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been found in Tenda i3 1.0.0.6(2204). Affected by this vulnerability is the function formwrlSSIDset of the file /goform/wifiSSIDset. The manipulation of the argument index/GO leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • i3
  • i3_firmware

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
i3i3_firmware

2 versions affected across 2 products

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-03-12: 4Technical Details · 2026-03-12: 303-12
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Full discourse4 posts
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-3971 - Tenda - i3 - https://www.redpacketsecurity.com/cve-alert-cve-2026-3971-tenda-i3/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-3971 #tenda #i3

    Post summary

    The tweet announces CVE-2026-3971 for Tenda i3 and links to a CVE alert page, providing minimal technical details.

    0000062
    3.5K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-3971 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-3971 #CVE-2026-3971 #CVE #High  #CyberSecurity #InfoSec https://t.co/8zsOXtr2lR

    Post summary

    The tweet announces a new vulnerability CVE-2026-3971 with a severity score of 8.8 affecting multiple products and links to the official NVD entry.

    0000071
    96 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-3971 A vulnerability has been found in Tenda i3 1.0.0.6(2204). Affected by this vulnerability is the function formwrlSSIDset of the file /goform/wifiSSIDset. The manipulatio… https://www.cve.org/CVERecord?id=CVE-2026-3971

    Post summary

    The entry highlights a vulnerability in Tenda i3 firmware—specifically the formwrlSSIDset function—without providing exploitation proof, patches, or evidence of active attacks.

    00000130
    56.7K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-3971: HIGH] Critical vulnerability discovered in Tenda i3 1.0.0.6(2204) allows remote attackers to trigger a stack-based buffer overflow via formwrlSSIDset function in /goform/wifiSSIDset file. Actio...#cve,CVE-2026-3971,#cybersecurity https://cvefind.com/CVE-2026-3971

    Post summary

    The tweet announces a high‑severity CVE‑2026‑3971 in Tenda i3 firmware, detailing a stack‑based buffer overflow via a Wi‑Fi SSID configuration endpoint, without providing PoC, exploit code, or mitigation strategies.

    0000043
    601 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendai3---
OStendai3_firmware1.0.0.6\(2204\)--

Explore more