CVE-2026-8138

8.8

Tenda · CX12L

A stack-based buffer overflow in Tenda CX12L routers allows remote attackers to execute arbitrary code via the startIp parameter in the SetPptpServerCfg endpoint.

Executive summary

A critical stack-based buffer overflow vulnerability in the Tenda CX12L router allows remote attackers to achieve arbitrary code execution and compromise the device.

Vulnerability

A stack-based buffer overflow exists within the formSetPPTPServer function at the /goform/SetPptpServerCfg endpoint, triggered by unbounded input processing of the startIp parameter by an unauthenticated attacker.

Business impact

A successful exploit can result in full device compromise, allowing malicious actors to manipulate network traffic, intercept sensitive communications, or use the compromised router as a pivot point for lateral movement into the internal network. The high CVSS score of 8.8 reflects the severe potential for total system control and remote execution without requiring prior authentication.

Remediation

Immediate Action: Apply firmware updates from the vendor as soon as they become available, or restrict management interfaces from external exposure.

Proactive Monitoring: Monitor network traffic for anomalous request patterns targeting the /goform/SetPptpServerCfg endpoint and watch for unexpected device reboots indicating denial of service attempts.

Compensating Controls: Deploy a Web Application Firewall or network access control lists to block malicious HTTP requests containing oversized startIp parameters destined for the management interface.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists via GitHub issue references.

Analyst recommendation

Administrators must treat this vulnerability with high urgency given the potential for remote code execution and network compromise. Since no official patch version is detailed in the current advisory, network perimeter controls should be enforced immediately to isolate affected devices from untrusted networks until vendor firmware updates can be applied.

More Tenda CVEs

Sources

Originally found and disclosed by lv1020 (VulDB User), per the CVE Program record.