CVE-2026-2870

8.8

Tenda · A21

A stack-based buffer overflow in the Tenda A21 router allows remote attackers to execute arbitrary code via the set_qosMib_list function.

Executive summary

A critical stack-based buffer overflow vulnerability in Tenda A21 devices enables remote code execution, posing a significant risk of full system compromise.

Vulnerability

This vulnerability is a stack-based buffer overflow occurring within the set_qosMib_list function of the /goform/formSetQosBand file. The flaw can be triggered remotely by a low-privileged authenticated attacker through the manipulation of the list argument.

Business impact

Successful exploitation allows an attacker to achieve remote code execution on the affected network device. This results in a complete loss of confidentiality, integrity, and availability for the gateway, potentially allowing an attacker to intercept network traffic or pivot into the internal network. Given the CVSS score of 8.8, this vulnerability represents a high-severity threat to business operations and network security.

Remediation

Immediate Action: Contact the vendor immediately to obtain the appropriate firmware update for version 1.0.0.0, as no official patch version is currently identified.

Proactive Monitoring: Review system and access logs for unusual traffic patterns originating from unauthorized accounts targeting the /goform/formSetQosBand endpoint.

Compensating Controls: Restrict administrative access to the router to trusted management subnets and disable remote management interfaces if they are not strictly required for business operations.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists and is attributed to the technical write-up provided in the referenced GitHub repository.

Analyst recommendation

Due to the availability of a public proof-of-concept and the potential for remote code execution, this vulnerability requires urgent attention. Administrators should prioritize isolating affected Tenda A21 devices from public-facing segments until a vendor-supplied firmware update is applied to remediate the buffer overflow.

More Tenda CVEs

Sources

Originally found and disclosed by hhsw34 (VulDB User), per the CVE Program record.