Description
The Tenda TX9 V22.03.02.05 firmware has a stack overflow vulnerability in the sub_4418CC function of the file /goform/SetNetControlList.
Published: 2026-07-20
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Tenda TX9 firmware version V22.03.02.05 contains a stack-based buffer overflow in the sub_4418CC function within the /goform/SetNetControlList endpoint, identified as CWE-121. This flaw can allow an attacker to overwrite critical memory areas and potentially execute arbitrary code on the device, compromising confidentiality, integrity, and availability of the network appliance.

Affected Systems

The vulnerability affects Tenda TX9 routers running firmware V22.03.02.05. No other vendors or product versions are listed as impacted.

Risk and Exploitability

The CVSS score of 9.8 classifies this issue as critical. Although the EPSS score is below 1%, indicating a low probability of widespread exploitation at this time, the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the /goform/SetNetControlList HTTP endpoint. Based on the description, it is inferred that an attacker with network reach could trigger the stack overflow to gain control of the device. Given the severity, a remote adversary with network reach could potentially exploit this flaw to compromise confidentiality, integrity, and availability of the device.

Generated by OpenCVE AI on July 30, 2026 at 19:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Tenda TX9 firmware to a version that removes the vulnerability when an official fix becomes available.
  • Apply a network ACL or firewall rule to block inbound access to the /goform/SetNetControlList path from untrusted networks.
  • Revoke or disable any administrative interfaces that expose the affected endpoint, or move the device to a network segment with stricter access controls.

Generated by OpenCVE AI on July 30, 2026 at 19:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Stack Overflow Vulnerability in Tenda TX9 Firmware /goform/SetNetControlList Endpoint

Sat, 25 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Stack Overflow Vulnerability in Tenda TX9 Firmware /goform/SetNetControlList Endpoint

Tue, 21 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Tenda
Tenda tx9
Vendors & Products Tenda
Tenda tx9

Tue, 21 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-121
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 20 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Description The Tenda TX9 V22.03.02.05 firmware has a stack overflow vulnerability in the sub_4418CC function of the file /goform/SetNetControlList.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-21T14:58:33.718Z

Reserved: 2024-10-28T00:00:00.000Z

Link: CVE-2024-51311

cve-icon Vulnrichment

Updated: 2026-07-21T14:20:51.368Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T20:00:20Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow