PT-2026-71958 · Tenda · Tenda G0
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Tenda G0 versions prior to 20260625
Description
A stack-based buffer overflow exists in the httpd web management interface. The issue occurs within the
addStaticRoute() function located in the /goform/module file. A remote attacker can trigger this by manipulating the staticRouteNet argument. A stack-based buffer overflow is a condition where a program writes more data to a buffer located on the stack than the buffer is allocated to hold, potentially leading to crashes or arbitrary code execution.Recommendations
Update Tenda G0 to a version released after 20260625.
As a temporary mitigation, restrict access to the
addStaticRoute() function within the httpd web management interface.Exploit
Fix
Buffer Overflow
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tenda G0