PT-2026-26645 · Tenda · Tenda A18 Pro

Lilukun

·

Published

2026-03-20

·

Updated

2026-03-22

·

CVE-2026-4491

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Tenda A18 Pro version 02.03.02.28
Description A stack-based buffer overflow exists in the fromSetIpMacBind function located in the /goform/SetIpMacBind file of the Tenda A18 Pro. Manipulation of the argument list to this function can trigger the overflow, allowing for remote exploitation. The exploit has been publicly disclosed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Stack Overflow

Weakness Enumeration

Related Identifiers

CVE-2026-4491

Affected Products

Tenda A18 Pro