CVE-2026-3804 – Tenda i3 Router Stack-Based Buffer Overflow

CVE-2026-3804 Stack Overflow CWE-121 Router RCE Risk
Overview
CVE-2026-3804 is a vulnerability in Tenda i3 router firmware version 1.0.0.6(2204) caused by improper input validation in the web management interface. Attackers can manipulate specific request parameters to trigger a stack-based buffer overflow, potentially leading to unauthorized control of the device.
If exploited, the flaw can allow memory corruption, service instability, and potential arbitrary code execution in router context.
Technical Specifications
| Attribute | Details |
|---|---|
| CVE ID | CVE-2026-3804 |
| Vulnerability Type | Stack-based buffer overflow (CWE-121) |
| CVSS Score | 7.4 (High) |
| Affected Product | Tenda i3 Wi-Fi router |
| Affected Firmware | 1.0.0.6(2204) |
| Vulnerable Endpoint | /goform/WifiMacFilterSet |
| Vulnerable Function | formWifiMacFilterSet |
| Vulnerable Parameter | index |
| Exploit Outcome | Potential arbitrary code execution, unauthorized control, or DoS |
Affected Products
- Tenda i3 routers running firmware
1.0.0.6(2204) - Devices exposing web management interface to local or internet-reachable networks
- Environments with remote administration enabled without strict access controls
- Legacy/unpatched home or SMB edge deployments
- Status: High risk until updated or isolated
Technical Details
Root Cause
- Input passed via the
indexparameter is not adequately validated. - Crafted payloads can exceed expected buffer boundaries in
formWifiMacFilterSet. - Memory corruption occurs on the stack, enabling crash or controlled overwrite conditions.
Vulnerable Path
- HTTP request targeting
/goform/WifiMacFilterSet - Maliciously manipulated
indexvalue triggers overflow in firmware handler
Security Consequence
- Stack corruption can lead to process crash (availability impact).
- Under favorable conditions, attacker may gain code execution/control in device context.
Attack Scenario
-
Target Discovery:
- Attacker identifies reachable Tenda i3 routers (internet-exposed or local network).
-
Crafted Request Delivery:
- Attacker sends malicious HTTP request to
/goform/WifiMacFilterSet.
- Attacker sends malicious HTTP request to
-
Parameter Manipulation:
indexparameter is populated with overflow-triggering payload.
-
Overflow Trigger:
- Firmware function fails to validate bounds and overwrites stack memory.
-
Post-Exploitation Outcome:
- Device may crash (DoS) or attacker may gain unauthorized control for persistence/traffic abuse.
Impact Assessment
- Unauthorized administrative control of router settings
- Malicious configuration changes (DNS/routing/firewall)
- Potential implantation of persistent malicious logic
- Interception or redirection of user traffic
- Increased risk of credential/session capture via MITM behavior
- Exposure of internal network patterns via compromised gateway
- Service crash or repeated instability from overflow exploitation
- Potential participation in botnet activity affecting network performance
- Loss of connectivity and operational disruption for dependent users
Mitigation Strategies
Immediate Actions
- Update firmware to latest vendor release as patches become available
- Disable remote administration where not required
- Restrict management access to trusted internal networks only
Detection and Monitoring
- Monitor logs for suspicious requests targeting
/goform/*endpoints - Alert on repeated malformed management requests and unexplained config changes
- Track unexpected reboot/crash patterns indicating exploitation attempts
Long-Term Risk Reduction
- Replace unsupported or unpatched routers with maintained models
- Segment edge management interfaces from untrusted network zones
- Periodically audit internet exposure of router administration services
Resources and References
Open-Source References
Last Updated: March 9, 2026