A vulnerability was identified in Tenda A18 15.13.07.13. The affected element is the function webCgiGetUploadFile of the file /cgi-bin/UploadCfg of the component Httpd Service. Such manipulation of the argument boundary leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used.
Metrics
Affected Vendors & Products
References
History
Mon, 23 Feb 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenda a18 Firmware
|
|
| CPEs | cpe:2.3:h:tenda:a18:-:*:*:*:*:*:*:* cpe:2.3:o:tenda:a18_firmware:15.13.07.13:*:*:*:*:*:*:* |
|
| Vendors & Products |
Tenda a18 Firmware
|
Mon, 23 Feb 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenda
Tenda a18 |
|
| Vendors & Products |
Tenda
Tenda a18 |
Sun, 22 Feb 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was identified in Tenda A18 15.13.07.13. The affected element is the function webCgiGetUploadFile of the file /cgi-bin/UploadCfg of the component Httpd Service. Such manipulation of the argument boundary leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used. | |
| Title | Tenda A18 Httpd Service UploadCfg webCgiGetUploadFile stack-based overflow | |
| Weaknesses | CWE-119 CWE-121 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-02-22T06:02:10.062Z
Updated: 2026-02-22T06:02:10.062Z
Reserved: 2026-02-21T05:00:32.389Z
Link: CVE-2026-2930
No data.
Status : Analyzed
Published: 2026-02-22T07:16:15.023
Modified: 2026-02-23T20:19:16.723
Link: CVE-2026-2930
No data.