Tenda · Tenda G0 · CVE-2026-19792
**Name of the Vulnerable Software and Affected Versions**
Tenda G0 versions prior to 20260625
**Description**
A buffer overflow exists in the httpd web management interface within the `/goform/module` file. The issue occurs in the `setPortMapping()` function when manipulating the `portMappingServer`, `porMappingtInternal`, or `portMappingExternal` arguments. This flaw allows a remote attacker to trigger the overflow.
**Recommendations**
Update Tenda G0 to a version released after 20260625.
As a temporary mitigation, restrict access to the `setPortMapping()` function in the httpd web management interface.