CVE-2026-51934
largeUnauthenticated Buffer Overflow RCE in Tenda A18 Router
A buffer overflow (CWE-120) exists in the fromSetCmdlineRun function of the Tenda A18 router firmware, version 15.13.07.09. Per the CVSS vector (AV:N/AC:L/PR:N/UI:N), the flaw is reachable over the network without authentication or user interaction, meaning a remote attacker can trigger it with a crafted request to the device's management interface. Successful exploitation permits arbitrary code execution with high impact on confidentiality, integrity, and availability — effectively full control of the router, which could enable traffic interception or use as a foothold into the local network. Owners and administrators of Tenda A18 routers are affected, especially any deployed with the web management interface exposed to the internet. There is no public proof-of-concept, the CVE is not in CISA KEV, and no in-the-wild exploitation is confirmed; EPSS estimates roughly a 0.6% chance of exploitation within 30 days.
What to do: No fixed firmware version is specified in the available data, so check Tenda's official support/download site for an updated A18 firmware and upgrade as soon as a patch is published. Until patched, disable remote/WAN administration and restrict the router's management interface to trusted LAN clients. Verify your current firmware against v15.13.07.09, the version explicitly named as affected.
| Tenda (Shenzhen Jixiang Tengda Technology Co., Ltd.) A18 wireless router | firmware v15.13.07.09 (the version named as affected; other firmware versions are not confirmed in the available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Buffer Overflow vulnerability in Shenzhen Jixiang Tengda Technology Co., Ltd. Tenda A18 v.15.13.07.09 allows a remote attacker to execute arbitrary code via the fromSetCmdlineRun function
- Weakness
- CWE-120
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.