A vulnerability was found in Tenda i3 1.0.0.6(2204). It has been declared as critical. Affected by this issue is the function formexeCommand of the file /goform/exeCommand. Executing a manipulation of the argument cmdinput can lead to stack-based buffer overflow.

This vulnerability appears as CVE-2026-3802. The attack may be performed from remote. In addition, an exploit is available.