CVE-2026-19792 PUBLISHED

Tenda G0 httpd web management interface module setPortMapping buffer overflow

Assigner: VulDB
Reserved: 13.08.2026 Published: 14.08.2026 Updated: 14.08.2026

A security flaw has been discovered in Tenda G0 up to 20260625. Impacted is the function setPortMapping of the file /goform/module of the component httpd web management interface. Performing a manipulation of the argument portMappingServer/porMappingtInternal/portMappingExternal results in buffer overflow. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
CVSS Score: 8.7

Product Status

Vendor Tenda
Product G0
Versions
  • Version 20260625 is affected

Credits

  • stksgg (VulDB User) reporter

References

Problem Types

  • Buffer Overflow CWE
  • Memory Corruption CWE