Description
The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EA38 function of the file /goform/SetVirtualServerCfg.
Published: 2026-07-20
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A stack overflow occurs in the SetVirtualServerCfg helper of the Tenda TX9 firmware. This overflow can overwrite control data on the stack when overly long configuration strings are submitted, potentially allowing an attacker to corrupt control flow or execute arbitrary code. Because the vulnerability exists in a gateway device that handles network traffic, exploitation could compromise confidentiality, integrity, and availability of the device and the network it serves. The weakness is identified as CWE-121.

Affected Systems

The flaw is present in Tenda TX9 routers running firmware version V22.03.02.20. No other product or version information has been disclosed. Vendors or distributors of this firmware should verify whether newer releases address the issue.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical severity, while the EPSS of less than 1% suggests that exploitation is presently uncommon. The vulnerability is not yet listed in the CISA KEV catalog. The attack likely proceeds over the network by sending a crafted request to /goform/SetVirtualServerCfg, leveraging the device’s management interface. No authentication requirement is mentioned, so the request could be made from any host able to reach the router’s control port.

Generated by OpenCVE AI on July 30, 2026 at 19:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Tenda TX9 firmware that contains the stack overflow fix.
  • If a firmware update is unavailable, disable the virtual server functionality or restrict access to the SetVirtualServerCfg interface to trusted local addresses only.
  • Monitor the device for abnormal traffic or configuration changes and isolate the router from critical network segments until patched.

Generated by OpenCVE AI on July 30, 2026 at 19:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Stack Overflow in Tenda TX9 Virtual Server Configuration

Wed, 29 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title Stack Overflow in Tenda TX9 Firmware Leading to Remote Code Execution

Fri, 24 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Stack Overflow in Tenda TX9 Firmware Leading to Remote Code Execution

Tue, 21 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Tenda
Tenda tx9
Vendors & Products Tenda
Tenda tx9

Tue, 21 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-121
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 20 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Description The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EA38 function of the file /goform/SetVirtualServerCfg.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-21T14:58:28.306Z

Reserved: 2024-10-28T00:00:00.000Z

Link: CVE-2024-51313

cve-icon Vulnrichment

Updated: 2026-07-21T14:20:09.597Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T20:00:20Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow