« Back to list

Tenda

Tenda W3 Firmware: vulnerabilities and CVEs

Tenda W3 Firmware has 7 published vulnerabilities, 7 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs7
Last 12 months7
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-4008High (7.4)1.0%—Mar 12, 2026
A flaw has been found in Tenda W3 1.0.0.3(2204). This issue affects some unknown processing of the file /goform/wifiSSIDset of the component POST Parameter Handler. Executing a manipulation of the argument index/GO can…
CVE-2026-4007High (7.4)1.0%—Mar 12, 2026
A vulnerability was detected in Tenda W3 1.0.0.3(2204). This vulnerability affects unknown code of the file /goform/wifiSSIDget of the component POST Parameter Handler. Performing a manipulation of the argument index…
CVE-2026-3976High (7.4)1.0%—Mar 12, 2026
A weakness has been identified in Tenda W3 1.0.0.3(2204). Impacted is the function formWifiMacFilterSet of the file /goform/WifiMacFilterSet of the component POST Parameter Handler. Executing a manipulation of the…
CVE-2026-3975High (7.4)1.0%—Mar 12, 2026
A security flaw has been discovered in Tenda W3 1.0.0.3(2204). This issue affects the function formWifiMacFilterGet of the file /goform/WifiMacFilterGet of the component POST Parameter Handler. Performing a manipulation…
CVE-2026-3974High (7.4)1.0%—Mar 12, 2026
A vulnerability was identified in Tenda W3 1.0.0.3(2204). This vulnerability affects the function formexeCommand of the file /goform/exeCommand of the component HTTP Handler. Such manipulation of the argument cmdinput…
CVE-2026-3973High (7.4)1.0%—Mar 12, 2026
A vulnerability was determined in Tenda W3 1.0.0.3(2204). This affects the function formSetAutoPing of the file /goform/setAutoPing of the component POST Parameter Handler. This manipulation of the argument ping1/ping2…
CVE-2026-3972High (7.4)0.74%—Mar 12, 2026
A vulnerability was found in Tenda W3 1.0.0.3(2204). Affected by this issue is the function formSetCfm of the file /goform/setcfm of the component HTTP Handler. The manipulation of the argument funcpara1 results in…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059 Command and Scripting Interpreter7
  2. T1210 Exploitation of Remote Services7

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Tenda