CVE-2026-2870
8.8Tenda · A21
A stack-based buffer overflow in the Tenda A21 router allows remote attackers to execute arbitrary code via the set_qosMib_list function.
Executive summary
A critical stack-based buffer overflow vulnerability in Tenda A21 devices enables remote code execution, posing a significant risk of full system compromise.
Vulnerability
This vulnerability is a stack-based buffer overflow occurring within the set_qosMib_list function of the /goform/formSetQosBand file. The flaw can be triggered remotely by a low-privileged authenticated attacker through the manipulation of the list argument.
Business impact
Successful exploitation allows an attacker to achieve remote code execution on the affected network device. This results in a complete loss of confidentiality, integrity, and availability for the gateway, potentially allowing an attacker to intercept network traffic or pivot into the internal network. Given the CVSS score of 8.8, this vulnerability represents a high-severity threat to business operations and network security.
Remediation
Immediate Action: Contact the vendor immediately to obtain the appropriate firmware update for version 1.0.0.0, as no official patch version is currently identified.
Proactive Monitoring: Review system and access logs for unusual traffic patterns originating from unauthorized accounts targeting the /goform/formSetQosBand endpoint.
Compensating Controls: Restrict administrative access to the router to trusted management subnets and disable remote management interfaces if they are not strictly required for business operations.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists and is attributed to the technical write-up provided in the referenced GitHub repository.
Analyst recommendation
Due to the availability of a public proof-of-concept and the potential for remote code execution, this vulnerability requires urgent attention. Administrators should prioritize isolating affected Tenda A21 devices from public-facing segments until a vendor-supplied firmware update is applied to remediate the buffer overflow.
More Tenda CVEs
Sources
Originally found and disclosed by hhsw34 (VulDB User), per the CVE Program record.
- VDB-347107 | Tenda A21 formSetQosBand set_qosMib_list stack-based overflow Vulnerability database entry
- VDB-347107 | CTI Indicators (IOB, IOC, IOA)
- Submit #754627 | Tenda A21 V1.0.0.1 Stack-based Buffer Overflow Third-party advisory
- Exploit / PoC
- tenda.com.cn