{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/g0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-19792"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["G0"],"_cs_severities":["high"],"_cs_tags":["remote-code-execution","buffer-overflow","router","cve-2026-19792"],"_cs_type":"threat","_cs_vendors":["Tenda"],"content_html":"\u003cp\u003eA critical buffer overflow vulnerability has been identified in the Tenda G0 router, specifically within the httpd web management interface. The flaw resides in the setPortMapping function found in the /goform/module file. An attacker can trigger this vulnerability by sending a maliciously crafted HTTP request with excessively large input values in the portMappingServer, porMappingtInternal, or portMappingExternal parameters.\u003c/p\u003e\n\u003cp\u003eThis issue is rated as high severity due to the potential for unauthenticated or authenticated remote code execution or a complete denial of service of the network device. The vulnerability affects all Tenda G0 firmware versions up to 20260625. Publicly available exploit code exists for this vulnerability, increasing the risk of active exploitation against vulnerable devices exposed to the internet. Defenders should prioritize isolating management interfaces of these devices from public access.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify exposed Tenda G0 management interfaces via scanners.\u003c/li\u003e\n\u003cli\u003eAttacker establishes a session or interacts with the /goform/module endpoint on the web management interface.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP POST request targeting the setPortMapping function.\u003c/li\u003e\n\u003cli\u003eAttacker injects a payload into the portMappingServer, porMappingtInternal, or portMappingExternal parameters.\u003c/li\u003e\n\u003cli\u003eThe target application fails to perform proper bounds checking on the input, causing a buffer overflow.\u003c/li\u003e\n\u003cli\u003eThe attacker overwrites the instruction pointer to redirect execution flow.\u003c/li\u003e\n\u003cli\u003eAttacker executes arbitrary code on the underlying device firmware.\u003c/li\u003e\n\u003cli\u003eFinal objective achieved, resulting in system compromise or persistent device disruption.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-19792 allows a remote attacker to achieve arbitrary code execution on affected Tenda G0 routers. This could lead to full device compromise, allowing for traffic interception, lateral movement into the local network, or permanent denial of service. The vulnerability is exploitable remotely, making any device with an exposed web management interface a target.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImplement immediate network-level access control to restrict access to the web management interface of Tenda G0 devices to known, trusted management segments only.\u003c/li\u003e\n\u003cli\u003eDisable remote access to the web management interface from the WAN side if not strictly required.\u003c/li\u003e\n\u003cli\u003eMonitor network traffic for HTTP POST requests directed at /goform/module containing unusual string lengths or shellcode patterns in the specified parameters.\u003c/li\u003e\n\u003cli\u003eEnsure firmware is updated to versions released after 20260625 if a vendor patch becomes available.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-14T06:06:48Z","date_published":"2026-08-14T06:06:48Z","id":"https://feed.craftedsignal.io/briefs/2026-08-tenda-g0-overflow/","summary":"Tenda G0 devices contain a remote buffer overflow vulnerability in the httpd management interface that allows for potential arbitrary code execution or denial of service.","title":"Remote Buffer Overflow Vulnerability in Tenda G0","url":"https://feed.craftedsignal.io/briefs/2026-08-tenda-g0-overflow/"}],"language":"en","title":"CraftedSignal Threat Feed - G0","version":"https://jsonfeed.org/version/1.1"}