CVE-2026-2140
HIGH SEVERITYCVSS Score & Metrics
Base Score
8.8 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Description
A vulnerability was identified in Tenda TX9 up to 22.03.02.10_multi. Affected by this issue is the function sub_4223E0 of the file /goform/setMacFilterCfg. Such manipulation of the argument deviceList leads to buffer overflow. The attack may be launched remotely. The exploit is publicly available and might be used.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-119
Source
NVD
Vendor
tenda
Product
tx9_firmware
External References
- https://github.com/MRAdera/IoT-Vuls/blob/main/tenda/tx9%20pro/setMacFilterCfg.md
- https://github.com/MRAdera/IoT-Vuls/blob/main/tenda/tx9%20pro/setMacFilterCfg.md#poc
- https://vuldb.com/?ctiid.344775
- https://vuldb.com/?id.344775
- https://vuldb.com/?submit.747251
- https://vuldb.com/?submit.749747
- https://www.tenda.com.cn/
Discussion (0)
Add Comment
No comments yet. Be the first!