A vulnerability was identified in Tenda TX9 up to 22.03.02.10_multi. Affected by this issue is the function sub_4223E0 of the file /goform/setMacFilterCfg. Such manipulation of the argument deviceList leads to buffer overflow. The attack may be launched remotely. The exploit is publicly available and might be used.
History

Tue, 10 Feb 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 10 Feb 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Tenda tx9 Firmware
CPEs cpe:2.3:h:tenda:tx9:-:*:*:*:*:*:*:*
cpe:2.3:o:tenda:tx9_firmware:*:*:*:*:*:*:*:*
Vendors & Products Tenda tx9 Firmware

Mon, 09 Feb 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Tenda
Tenda tx9
Vendors & Products Tenda
Tenda tx9

Sun, 08 Feb 2026 07:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in Tenda TX9 up to 22.03.02.10_multi. Affected by this issue is the function sub_4223E0 of the file /goform/setMacFilterCfg. Such manipulation of the argument deviceList leads to buffer overflow. The attack may be launched remotely. The exploit is publicly available and might be used.
Title Tenda TX9 setMacFilterCfg sub_4223E0 buffer overflow
Weaknesses CWE-119
CWE-120
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2026-02-08T07:02:07.944Z

Updated: 2026-02-10T21:16:36.859Z

Reserved: 2026-02-06T21:02:58.555Z

Link: CVE-2026-2140

cve-icon Vulnrichment

Updated: 2026-02-10T21:16:32.325Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-08T07:16:01.577

Modified: 2026-02-10T19:28:33.607

Link: CVE-2026-2140

cve-icon Redhat

No data.