CVE-2026-4489 Details
Description
A vulnerability was detected in Tenda A18 Pro 02.03.02.28. This vulnerability affects the function form_fast_setting_wifi_set of the file /goform/fast_setting_wifi_set. The manipulation results in stack-based buffer overflow. The attack may be launched remotely. The exploit is now public and may be used.
A critical stack-based buffer overflow vulnerability has been identified in the Tenda A18 Pro router, specifically in the firmware version 02.03.02.28. The issue arises in the Wi-Fi configuration function 'form_fast_setting_wifi_set', located within the '/goform/fast_setting_wifi_set' endpoint. This vulnerability allows remote exploitation by overwriting a fixed-size stack buffer with user-controlled data, potentially leading to arbitrary code execution with root privileges or causing a denial-of-service condition by crashing the device's management interface.
Users are advised to update to a version of the firmware that addresses this vulnerability. Tenda has not provided specific guidance on which version to update to, but users should check the Tenda website or contact Tenda support for more information.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 20, 2026CISA-ADP
Assessed Mar 20, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/lilukun337/cve/issues/1 | [email protected] | ExploitIssue TrackingRemedy |
| https://vuldb.com/?ctiid.352015 | [email protected] | Content Wall |
| https://vuldb.com/?id.352015 | [email protected] | AdvisoryExploitPartial Content |
| https://vuldb.com/?submit.773619 | [email protected] | Technical Description |
| https://www.tenda.com.cn/ | [email protected] | Vendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | [email protected] |
| CWE-121 | Stack-based Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Tenda A18 Pro | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 20, 2026 | New CVE Received | [email protected] |
Volerion