Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-3974

A vulnerability was identified in Tenda W3 1.0.0.3(2204). This vulnerability affects the function formexeCommand of the file /goform/exeCommand of the component HTTP Handler. Such manipulation of the argument cmdinput leads to stack-based buffer overflow. The attack may be performed from remote. The exploit is publicly available and might be used.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 15.1%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 9.0
Products affected by CVE-2026-3974
  • Tenda » W3 » Version: N/A
    cpe:2.3:h:tenda:w3:-
  • Tenda » W3 Firmware » Version: 1.0.0.3(2204)
    cpe:2.3:o:tenda:w3_firmware:1.0.0.3(2204)


Contact Us

Shodan ® - All rights reserved