Executive brief
The Tenda A18 is a wireless router used to provide internet connectivity to homes and small businesses. A buffer overflow vulnerability in its firmware allows a remote attacker to execute arbitrary code on the device, potentially compromising network security and enabling unauthorized access to connected devices and data.
Technical details
This vulnerability is a buffer overflow in the fromSetCmdlineRun function within Tenda A18 firmware version 15.13.07.09. The vulnerability can be triggered remotely without authentication, allowing an attacker to overflow a buffer and execute arbitrary code with device privileges. The attack vector is network-based, requiring no user interaction or authentication. Successful exploitation grants the attacker complete control over the router, enabling network interception, device compromise, and lateral movement into connected networks.
Affected products
- Tenda A18 15.13.07.09
Timeline
- 2026-09-01: disclosed