CVE-2026-2139

HIGH

Tenda Tx9 Firmware < 22.03.02.10 - Memory Corruption

Title source: rule
STIX 2.1

Description

A vulnerability was determined in Tenda TX9 up to 22.03.02.10_multi. Affected by this vulnerability is the function sub_432580 of the file /goform/fast_setting_wifi_set. This manipulation of the argument ssid causes buffer overflow. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.

Scores

CVSS v3 8.8
EPSS 0.0011
EPSS Percentile 29.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-120 CWE-119
Status published
Products (1)
tenda/tx9_firmware < 22.03.02.10
Published Feb 08, 2026
Tracked Since Feb 18, 2026