CVE-2026-4567 - Vulnerability Analysis
CriticalCVSS: 9.8Last Updated: March 23, 2026
Tenda A15 - Buffer Overflow
Overview
Tenda A15 15.13.07.13 contains a stack-based buffer overflow caused by manipulation of the "File" argument in /cgi-bin/UploadCfg, letting remote attackers execute arbitrary code, exploit requires crafted request.
Severity & Score
Impact
Remote attackers can execute arbitrary code, potentially leading to full system compromise.
Mitigation
Update to the latest version.
References
- https://vuldb.com/?submit.775156
- https://www.tenda.com.cn/
- https://github.com/942384053/cve/issues/3
- https://github.com/user-attachments/files/25824036/Tenda.A15.V15.13.07.13.Unauthenticated.Stack-based.Buffer.Overflow.in._cgi-bin_UploadCfg.zip
- https://vuldb.com/?ctiid.352404
- https://vuldb.com/?id.352404
Social Media Activity(4 posts)
š“ CVE-2026-4567 - Critical (9.8) A vulnerability has been found in Tenda A15 15.13.07.13. The impacted element is the function UploadCfg of the file /cgi-bin/UploadCfg. The manipulation of the argument File leads to stack-based buffer overflow. The attack may be initiated remotel... š https://www.thehackerwire.com/vulnerability/CVE-2026-4567/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postš„ CVE-2026-4567: Critical stack buffer overflow in Tenda A15 (v15.13.07.13). Remote, unauthenticated code execution possible via /cgi-bin/UploadCfg. Patch or restrict access immediately! https://radar.offseq.com/threat/cve-2026-4567-stack-based-buffer-overflow-in-tenda-27ff1845 #OffSeq #infosec #routersecurity #CVE20264567
View original postš“ CVE-2026-4567 - Critical (9.8) A vulnerability has been found in Tenda A15 15.13.07.13. The impacted element is the function UploadCfg of the file /cgi-bin/UploadCfg. The manipulation of the argument File leads to stack-based buffer overflow. The attack may be initiated remotel... š https://www.thehackerwire.com/vulnerability/CVE-2026-4567/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postš„ CVE-2026-4567: Critical stack buffer overflow in Tenda A15 (v15.13.07.13). Remote, unauthenticated code execution possible via /cgi-bin/UploadCfg. Patch or restrict access immediately! https://radar.offseq.com/threat/cve-2026-4567-stack-based-buffer-overflow-in-tenda-27ff1845 #OffSeq #infosec #routersecurity #CVE20264567
View original postRelated Resources
Details
- CVE ID
- CVE-2026-4567
- Severity
- Critical
- CVSS Score
- 9.8
- Type
- buffer_overflow
- Status
- new
- EPSS
- 0.0%
- Social Posts
- 4
CWE
- CWE-119
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H