CVE-2026-51934
9.8Shenzhen Jixiang Tengda Technology Co., Ltd. · Tenda A18
A buffer overflow vulnerability in the Tenda A18 router allows unauthenticated remote attackers to execute arbitrary code by sending malicious input to the fromSetCmdlineRun function.
Executive summary
A critical buffer overflow vulnerability in the Tenda A18 router allows unauthenticated remote code execution, posing a severe threat to network integrity.
Vulnerability
This is a buffer overflow vulnerability triggered via the fromSetCmdlineRun function. The CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms that the attack requires no authentication or user interaction.
Business impact
The vulnerability carries a CVSS score of 9.8, indicating a critical severity level. Successful exploitation grants an attacker full control over the affected device, which can lead to complete compromise of network traffic, unauthorized access to internal resources, and the potential for lateral movement within the environment.
Remediation
Immediate Action: Organizations should restrict management interface access to trusted networks and check the official Tenda support website for firmware updates addressing this buffer overflow.
Proactive Monitoring: Monitor device logs for unusual traffic patterns or unexpected service restarts that may indicate exploitation attempts against the administrative functions.
Compensating Controls: Implement network-level access control lists (ACLs) to block external access to the Tenda A18 management interface, effectively isolating the vulnerable function from the public internet.
Exploitation status
Public Exploit Available: Yes, a proof-of-concept exists as documented in the GitHub repository referenced in the CVE record.
Analyst recommendation
Given the critical nature of this vulnerability and the availability of a public proof-of-concept, immediate action is required to secure the Tenda A18 devices. Administrators must prioritize restricting external access to the device management interface until a vendor-supplied patch is identified and applied. Failure to mitigate this risk leaves the network exposed to potential remote code execution by unauthenticated attackers.
More Shenzhen Jixiang Tengda Technology Co., Ltd. CVEs
History
CVE Brief tracked this CVE 5 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 9.8 (3.1)
- Analyst report written
- Published in the daily brief critical section, early-warning entry