GHSA-w66q-5x8w-9jjmHighCVSS 8.8
A security flaw has been discovered in Tenda G0 up to 20260625. Impacted is the function...
🔗 CVE IDs covered (1)
📋 Description
A security flaw has been discovered in Tenda G0 up to 20260625. Impacted is the function setPortMapping of the file /goform/module of the component httpd web management interface. Performing a manipulation of the argument portMappingServer/porMappingtInternal/portMappingExternal results in buffer overflow. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
🔗 References (8)
- https://nvd.nist.gov/vuln/detail/CVE-2026-19792
- https://github.com/lipenghai/iot_bug/blob/main/Tenda/G0/3.md
- https://vuldb.com/cve/CVE-2026-19792
- https://vuldb.com/submit/868929
- https://vuldb.com/vuln/389758
- https://vuldb.com/vuln/389758/cti
- https://www.tenda.com.cn
- https://github.com/advisories/GHSA-w66q-5x8w-9jjm