Junglewise Threat Intelligence

CVE-2026-51934: Tenda A18 buffer overflow in fromSetCmdlineRun

CVE-2026-51934 · Severity: critical · CVSS 9.8 · Published 2026-09-01

Vendors: Tenda.

Executive brief

The Tenda A18 is a wireless router used to provide internet connectivity to homes and small businesses. A buffer overflow vulnerability in its firmware allows a remote attacker to execute arbitrary code on the device, potentially compromising network security and enabling unauthorized access to connected devices and data.

Technical details

This vulnerability is a buffer overflow in the fromSetCmdlineRun function within Tenda A18 firmware version 15.13.07.09. The vulnerability can be triggered remotely without authentication, allowing an attacker to overflow a buffer and execute arbitrary code with device privileges. The attack vector is network-based, requiring no user interaction or authentication. Successful exploitation grants the attacker complete control over the router, enabling network interception, device compromise, and lateral movement into connected networks.

Affected products

  • Tenda A18 15.13.07.09

Timeline

  • 2026-09-01: disclosed

References