CVE detail
CVE-2026-2930
A vulnerability was identified in Tenda A18 15.13.07.13. The affected element is the function webCgiGetUploadFile of the file /cgi-bin/UploadCfg of the component Httpd Service. Such manipulation of the argument boundary leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 17.9 · diversity 11.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
5 source links · newest first
- https://www.tenda.com.cn/www.tenda.com.cn
No excerpt available.
Release Noteswww.tenda.com.cnFeb 22, 2026, 7:16 AM - https://vuldb.com/?submit.755227vuldb.com
No excerpt available.
Exploitvuldb.comFeb 22, 2026, 7:16 AM - https://vuldb.com/?id.347277vuldb.com
No excerpt available.
Exploitvuldb.comFeb 22, 2026, 7:16 AM - https://vuldb.com/?ctiid.347277vuldb.com
No excerpt available.
Exploitvuldb.comFeb 22, 2026, 7:16 AM No excerpt available.
Exploitgithub.comFeb 22, 2026, 7:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-2877CVSS 7.4 · High
A vulnerability has been found in Tenda A18 15.13.07.13. This affects the function strcpy of the file /goform/WifiExtraSet of the component Httpd Service. The manipulation of the…
- CVE-2026-2876CVSS 7.4 · High
A vulnerability was determined in Tenda A18 15.13.07.13. This affects the function parse_macfilter_rule of the file /goform/setBlackRule. This manipulation of the argument deviceL…
- CVE-2025-0848CVSS 7.1 · High
A vulnerability was found in Tenda A18 up to 15.13.07.09. It has been rated as critical. This issue affects the function SetCmdlineRun of the file /goform/SetCmdlineRun of the com…
- CVE-2024-32305CVSS 8.8 · High
Tenda A18 v15.03.05.05 firmware has a stack overflow vulnerability located via the PPW parameter in the fromWizardHandle function.
- CVE-2026-16248CVSS 7.4 · High
A vulnerability was found in Tenda AC10 16.03.10.09_multi_TDE01. This issue affects the function fromAdvSetLanip of the file /goform/AdvSetLanip of the component httpd/netctrl. Th…
- CVE-2026-16097CVSS 8.7 · High
A vulnerability was found in Shibby Tomato 1.28. This vulnerability affects the function sub_42537C of the component Scheduler Name Handler. The manipulation of the argument a1 re…