216.73.216.133

CVE-2026-2909

· Published 22/02/2026 02:16 · Modified 23/02/2026 20:21

Labels: CVE-2026-2909 2026-02-22CVE-2026-2909CWE-119[email protected]

Essential information

Published
22/02/2026 02:16
Modified
23/02/2026 20:21
Author
Creator
CVSS
7.4 HIGH (v3) 7.4 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A vulnerability was detected in Tenda HG9 300001138. This affects an unknown part of the file /boaform/formPing of the component Diagnostic Ping Endpoint. Performing a manipulation of the argument pingAddr results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
tenda / hg9 firmware cpe:2.3:o:tenda:hg9_firmware:300001138:*:*:*:*:*:*:*
tenda / hg9 cpe:2.3:h:tenda:hg9:-:*:*:*:*:*:*:*

References