Junglewise Threat Intelligence

CVE-2026-19792: Tenda G0 buffer overflow in setPortMapping

CVE-2026-19792 · Severity: high · CVSS 8.8 · Published 2026-08-14

Technologies: Tenda G0. Vendors: Tenda.

Executive brief

The Tenda G0 is a network appliance with a web-based management interface. A buffer overflow vulnerability exists in the port mapping configuration function that allows remote attackers to send specially crafted requests without authentication, potentially leading to code execution and complete device compromise.

Technical details

A buffer overflow vulnerability exists in the setPortMapping function of the Tenda G0 httpd web management interface (/goform/module). The vulnerability stems from unsafe use of sprintf() to write attacker-controlled parameters (portMappingServer, porMappingtInternal, portMappingExternal) into a fixed 256-byte stack buffer without length validation. An attacker can send a specially crafted HTTP request with oversized values for these parameters to overflow the buffer. The attack is network-reachable and does not require authentication. Successful exploitation allows arbitrary code execution on the device. Public exploits have been released.

Affected products

  • Tenda G0 up to 20260625

Timeline

  • 2026-08-14: disclosed
  • exploited: Public exploit released

References

Related threats