Description
The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_425964 function of the file /goform/SetOnlineDevName
Published: 2026-07-20
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Tenda TX9 V22.03.02.20 firmware contains a buffer overflow in the sub_425964 function that processes the online device name via the /goform/SetOnlineDevName interface, allowing a crafted input to overwrite the stack and potentially execute arbitrary code, a flaw classified as CWE-121 and rated with a CVSS score of 9.8, indicating critical severity.

Affected Systems

The vulnerable device is the Tenda TX9 wireless router running firmware version V22.03.02.20; no additional versions are documented as affected in the provided information.

Risk and Exploitability

Although the EPSS score is below 1%, indicating rare exploitation at present, the high CVSS score and absence from CISA KEV do not mitigate the significant risk; based on the description, it is inferred that attackers could target the publicly exposed management interface to deliver malicious device names, trigger the stack overflow, and potentially gain remote code execution capabilities on the router, especially in networks where the web interface is accessible locally.

Generated by OpenCVE AI on July 30, 2026 at 19:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the device firmware to the latest version that resolves the stack overflow flaw.
  • If an upgrade is not immediately possible, restrict or block the /goform/SetOnlineDevName endpoint by configuring firewall rules or placing the router on a separate VLAN to limit local network access to the web interface.
  • Consider isolating the router on a dedicated network segment or implementing network segmentation to reduce exposure to the vulnerable interface.

Generated by OpenCVE AI on July 30, 2026 at 19:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Stack Overflow via Device Name Setting on Tenda TX9 Router Firmware

Wed, 29 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title Stack Overflow in Tenda TX9 Firmware SetOnlineDevName Endpoint

Fri, 24 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Stack Overflow in Tenda TX9 Firmware SetOnlineDevName Endpoint

Tue, 21 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Tenda
Tenda tx9
Vendors & Products Tenda
Tenda tx9

Tue, 21 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-121
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 20 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Description The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_425964 function of the file /goform/SetOnlineDevName
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-21T14:58:11.507Z

Reserved: 2024-10-28T00:00:00.000Z

Link: CVE-2024-51315

cve-icon Vulnrichment

Updated: 2026-07-21T14:16:02.741Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T20:00:20Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow