Impact
A buffer overflow exists in the setPortMapping function of Tenda G0’s httpd web management interface. Malformed input to the portMappingServer, portMappingInternal, or portMappingExternal arguments can cause an overflow, potentially allowing an attacker to execute arbitrary code on the device. The vulnerability is exploitable from remote attackers through the web interface, and a public exploit has already been released.
Affected Systems
Tenda G0 devices running firmware versions up to 20260625 contain the flaw. The affected component is the httpd web management interface, specifically the /goform/module handler for the setPortMapping function.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity, and the vulnerability can be accessed remotely, which increases the window for exploitation. EPSS data is unavailable, but the publication of a public exploit and remote nature of the attack suggest a non‑negligible risk. The vulnerability is not listed in the CISA KEV catalog, but the combination of high severity, public exploit, and remote access makes it a priority for mitigation.
OpenCVE Enrichment