CVE-2026-19790
8.8Tenda · G0
Tenda G0 devices are vulnerable to a stack-based buffer overflow, which can lead to memory corruption and potential system compromise.
Executive summary
A memory corruption vulnerability in Tenda G0 devices permits authenticated attackers to trigger a stack-based buffer overflow, risking system availability and integrity.
Vulnerability
The device suffers from stack-based buffer overflow (CWE-121) and memory corruption (CWE-119) vulnerabilities. The attack vector is network-based and requires low-level authentication (PR:L) to trigger the vulnerable function.
Business impact
This vulnerability carries a CVSS score of 8.8, reflecting the high potential for system compromise. Exploitation could allow an attacker to disrupt critical networking services or gain a foothold within the network, leading to data exfiltration or lateral movement.
Remediation
Immediate Action: Limit management access to the G0 interface to authorized personnel and trusted internal networks.
Proactive Monitoring: Review device logs for suspicious activity or abnormal system behavior that could suggest an ongoing exploitation attempt.
Compensating Controls: Implement network-level access control lists to ensure only designated management workstations can communicate with the device.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Security teams must treat this vulnerability with high urgency. Ensure the device management interface is not exposed to the public internet and verify that all administrative accounts are secured with strong credentials while awaiting a formal firmware update from the vendor.