ZeroHour

CVE-2026-51934

large

Unauthenticated Buffer Overflow RCE in Tenda A18 Router

CVSS 3.1
9.8 critical
EPSS
<1%p48
Published
()
Modified
AI analysis

A buffer overflow (CWE-120) exists in the fromSetCmdlineRun function of the Tenda A18 router firmware, version 15.13.07.09. Per the CVSS vector (AV:N/AC:L/PR:N/UI:N), the flaw is reachable over the network without authentication or user interaction, meaning a remote attacker can trigger it with a crafted request to the device's management interface. Successful exploitation permits arbitrary code execution with high impact on confidentiality, integrity, and availability — effectively full control of the router, which could enable traffic interception or use as a foothold into the local network. Owners and administrators of Tenda A18 routers are affected, especially any deployed with the web management interface exposed to the internet. There is no public proof-of-concept, the CVE is not in CISA KEV, and no in-the-wild exploitation is confirmed; EPSS estimates roughly a 0.6% chance of exploitation within 30 days.

What to do: No fixed firmware version is specified in the available data, so check Tenda's official support/download site for an updated A18 firmware and upgrade as soon as a patch is published. Until patched, disable remote/WAN administration and restrict the router's management interface to trusted LAN clients. Verify your current firmware against v15.13.07.09, the version explicitly named as affected.

Affected
Tenda (Shenzhen Jixiang Tengda Technology Co., Ltd.) A18 wireless routerfirmware v15.13.07.09 (the version named as affected; other firmware versions are not confirmed in the available data)
Estimated exposure
largelikely on the order of 100,000+ deployed A18 routers; the internet-exposed subset is unknown — Tenda is a mass-market consumer/SOHO router brand whose models are widely retailed, and consumer routers are frequently left with remote management exposed to the WAN, but no public scan or active-install data exists for this specific…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Buffer Overflow vulnerability in Shenzhen Jixiang Tengda Technology Co., Ltd. Tenda A18 v.15.13.07.09 allows a remote attacker to execute arbitrary code via the fromSetCmdlineRun function

Weakness
CWE-120
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.