Description
The Tenda TX9 V22.03.02.20 firmware has a denial of service vulnerability in the update_dev_name function of the file /goform/SetOnlineDevName
Published: 2026-07-20
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Tenda TX9 firmware possesses a denial of service flaw in the update_dev_name function of the /goform/SetOnlineDevName endpoint. The resource exhaustion condition that can make the device unresponsive. This weakness is categorized as CWE‑400 and compromises the availability of the router for any connected users.

Affected Systems

Affected devices include the Tenda TX9 router running firmware version V22.03.02.20. The vulnerability was documented by Tenda's own download page and an online advisory that references the /goform/SetOnlineDevName path.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity level, while the EPSS score of less than 1% signals a very low but non‑zero likelihood of exploitation in the wild. The flaw is not listed in CISA's KEV catalog. The likely attack vector involves remotely crafting requests to the /goform/SetOnlineDevName endpoint, but this is inferred from the description and not explicitly stated. No additional exploitation prerequisites are noted in the description.

Generated by OpenCVE AI on July 30, 2026 at 19:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the TX9 firmware to the latest version access to the device's administrative web interface to reduce exposure.
  • Monitor device logs and performance for repeated attempts to change the device name, and isolate the device if abnormal activity is detected.
  • Apply firewall rules to limit external access to the router's management interface, ensuring only trusted IP addresses can reach /goform/SetOnlineDevName.

Generated by OpenCVE AI on July 30, 2026 at 19:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Denial of Service via SetOnlineDevName Endpoint in Tenda TX9 Router Firmware

Wed, 29 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title Denial of Service via Malformed Device Name Update in Tenda TX9 Firmware

Sat, 25 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Denial of Service via Malformed Device Name Update in Tenda TX9 Firmware

Wed, 22 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Tenda
Tenda tx9
Vendors & Products Tenda
Tenda tx9

Tue, 21 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 20 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Description The Tenda TX9 V22.03.02.20 firmware has a denial of service vulnerability in the update_dev_name function of the file /goform/SetOnlineDevName
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-21T14:58:05.589Z

Reserved: 2024-10-28T00:00:00.000Z

Link: CVE-2024-51316

cve-icon Vulnrichment

Updated: 2026-07-21T14:13:59.551Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T20:00:20Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption