CVE-2026-2140

HIGH

Tenda Tx9 Firmware < 22.03.02.10 - Memory Corruption

Title source: rule
STIX 2.1

Description

A vulnerability was identified in Tenda TX9 up to 22.03.02.10_multi. Affected by this issue is the function sub_4223E0 of the file /goform/setMacFilterCfg. Such manipulation of the argument deviceList leads to buffer overflow. The attack may be launched remotely. The exploit is publicly available and might be used.

Scores

CVSS v3 8.8
EPSS 0.0004
EPSS Percentile 12.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-120 CWE-119
Status published
Products (1)
tenda/tx9_firmware < 22.03.02.10
Published Feb 08, 2026
Tracked Since Feb 18, 2026