๐Ÿ” CVE Alert

CVE-2026-19792

HIGH 8.8

Tenda G0 httpd web management interface module setPortMapping buffer overflow

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

A security flaw has been discovered in Tenda G0 up to 20260625. Impacted is the function setPortMapping of the file /goform/module of the component httpd web management interface. Performing a manipulation of the argument portMappingServer/porMappingtInternal/portMappingExternal results in buffer overflow. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.

CWE CWE-120 CWE-119
Vendor tenda
Product g0
Published Aug 14, 2026
Stay Ahead of the Next One

Get instant alerts for tenda g0

Be the first to know when new high vulnerabilities affecting tenda g0 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Tenda / G0
20260625

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/389758 vuldb.com: https://vuldb.com/vuln/389758/cti vuldb.com: https://vuldb.com/cve/CVE-2026-19792 vuldb.com: https://vuldb.com/submit/868929 github.com: https://github.com/lipenghai/iot_bug/blob/main/Tenda/G0/3.md tenda.com.cn: https://www.tenda.com.cn/

Credits

๐Ÿ” stksgg (VulDB User)