CVE-2026-4490
8.8Tenda · A18 Pro
A stack-based buffer overflow exists in the Tenda A18 Pro router within the setSchedWifi function, allowing authenticated attackers to cause a denial of service or execute arbitrary code.
Executive summary
A heap-based buffer overflow vulnerability in the Tenda A18 Pro router, specifically within the Wi-Fi scheduling configuration, poses a significant risk of remote code execution or system instability.
Vulnerability
The vulnerability exists in the /goform/openSchedWifi endpoint due to the use of the unsafe strcpy function. An authenticated attacker can supply oversized parameters to the schedStartTime or schedEndTime fields, causing memory corruption that may lead to service crashes or arbitrary code execution.
Business impact
Successful exploitation of this vulnerability could result in a complete loss of availability for the affected Tenda networking device, disrupting network connectivity for all dependent users and systems. Given the CVSS score of 8.8, the potential for arbitrary code execution creates a critical risk, as an attacker could gain persistent control over the networking infrastructure to facilitate further lateral movement or data interception within the internal network.
Remediation
Immediate Action: Administrators should immediately restrict access to the web management interface and check the Tenda support portal for firmware updates that address this buffer overflow.
Proactive Monitoring: Monitor system logs for repeated crashes of the httpd service or unusual request patterns targeting the /goform/openSchedWifi endpoint.
Compensating Controls: Implement strict network access control lists (ACLs) to ensure the management interface is only accessible from trusted administrative IP addresses, effectively mitigating the risk from unauthorized users.
Exploitation status
Public Exploit Available: Yes — a functional proof-of-concept exploit is available via the researcher's GitHub repository.
Analyst recommendation
The severity of this flaw, combined with the availability of a public proof-of-concept, necessitates immediate attention. Administrators must prioritize the application of vendor patches or, at a minimum, isolate the management interface from the network to prevent unauthorized access and potential code execution.
More Tenda CVEs
Sources
Originally found and disclosed by lilukun (VulDB User), per the CVE Program record.
- VDB-352016 | Tenda A18 Pro openSchedWifi setSchedWifi stack-based overflow Vulnerability database entry
- VDB-352016 | CTI Indicators (IOB, IOC, IOA)
- Submit #773670 | Tenda A18pro V02.03.02.28 Stack-based Buffer Overflow Third-party advisory
- Exploit / PoC
- tenda.com.cn