CVE-2026-4007Disclosure(tenda / w3)

LOWCVSS 7.4 · HIGH

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Prioritize remediation for tenda w3 systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability was detected in Tenda W3 1.0.0.3(2204). This vulnerability affects unknown code of the file /goform/wifiSSIDget of the component POST Parameter Handler. Performing a manipulation of the argument index results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit is now public and may be used.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121CWE-787

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • w3
  • w3_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 5 classified signals
  • Peaked 1d ago at 5 mentions (2026-03-12); latest day: 1
  • 6 total mentions across 2 days

Affected systems

Vendors
Products
w3w3_firmware

2 versions affected across 2 products

Deep dive

Activity timeline6 mentions / 2d
01345Mentions · 2026-03-12: 5Mentions · 2026-03-13: 1Active Exploitation · 2026-03-13: 1Technical Details · 2026-03-12: 403-1203-13
Signal classification2 categories
Disclosure
583.3%
Active Exploitation
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-125
Disclosure5
2026-03-131
Active Exploitation1
Full discourse6 posts
  • EdgeDetectOps@EdgeDetectOps
    Active Exploitation

    At first it looked normal — firmware version 1.0.0.3, same as always. But when they dug deeper into CVE-2026-4007, they realized their "stable" network backbone had been compromised for weeks through unknown code execution paths they never knew existed.

    Post summary

    The post indicates that CVE-2026-4007 has been actively exploited, compromising the network for weeks via unknown code execution paths.

    1000027
    14 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4007 A vulnerability was detected in Tenda W3 1.0.0.3(2204). This vulnerability affects unknown code of the file /goform/wifiSSIDget of the component POST Parameter Handler.… https://www.cve.org/CVERecord?id=CVE-2026-4007

    Post summary

    The text announces CVE-2026‑4007, a vulnerability in the Tenda W3 firmware affecting the /goform/wifiSSIDget POST parameter handler, without providing PoC, exploit, or patch details.

    00001102
    56.7K followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-4007 - Tenda - W3 - https://www.redpacketsecurity.com/cve-alert-cve-2026-4007-tenda-w3/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-4007 #tenda #w3

    Post summary

    The tweet announces the new CVE-2026-4007 affecting Tenda W3, but provides no further technical, PoC, or exploitation details.

    0000076
    3.6K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-4007 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4007 #CVE-2026-4007 #CVE #High  #CyberSecurity #InfoSec https://t.co/SI2rkIpYco

    Post summary

    The tweet announces CVE‑2026‑4007 with a severity rating of 8.8 and high risk level, linking to the NVD entry but lacking any proof‑of‑concept, exploit, or mitigation information.

    0000046
    96 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4007 - Tenda W3 POST Parameter wifiSSIDget stack-based overflow Intel Report: https://ift.tt/AeC1a2Z

    Post summary

    The alert announces CVE‑2026‑4007, a stack‑based overflow in Tenda W3 routers triggered via the wifiSSIDget POST parameter, and provides an intel report link.

    0000034
    342 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-4007: HIGH] Critical security alert: Tenda W3 1.0.0.3(2204) has a remote stack-based buffer overflow vulnerability. Attackers can exploit this remotely. Take immediate action.#cve,CVE-2026-4007,#cybersecurity https://cvefind.com/CVE-2026-4007

    Post summary

    A critical stack‑based buffer overflow in Tenda W3 routers is disclosed, with no evidence of exploit code or current exploitation; immediate action is recommended.

    0000051
    601 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendaw3---
OStendaw3_firmware1.0.0.3\(2204\)--

Explore more