Description
A vulnerability was detected in Tenda HG9 300001138. This affects an unknown part of the file /boaform/formPing of the component Diagnostic Ping Endpoint. Performing a manipulation of the argument pingAddr results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Published: 2026-02-22
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in Tenda HG9 firmware 300001138 allows an attacker to send a specially crafted pingAddr argument to the /boaform/formPing endpoint, causing a buffer overflow on the device’s stack. This flaw can lead to arbitrary code execution from a remote host, compromising confidentiality, integrity, and availability of the network device.

Affected Systems

The affected device is the Tenda HG9 model running firmware version 300001138. Any installation of this firmware that exposes the Diagnostic Ping Endpoint to external networks is vulnerable. The vulnerability is specific to the formPing component and requires the device to be reachable over the network.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity. The EPSS score of less than 1% indicates a very low but non‑zero probability of exploitation, possibly due to targeted actors. The flaw is not listed in CISA’s KEV catalog, implying no known widespread exploitation. However, the remote nature of the attack and the potential for arbitrary code execution make it a high‑risk threat if left unmitigated. An attacker would need network access to the device and could exploit the overflow simply by crafting an HTTP request to /boaform/formPing with an oversized pingAddr parameter.

Generated by OpenCVE AI on April 17, 2026 at 16:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Tenda HG9 firmware to the latest version that includes the patch for the formPing buffer overflow.
  • If an immediate firmware upgrade is not possible, block or disable the /boaform/formPing endpoint and restrict network access to the device to trusted internal hosts only.
  • Apply input validation controls or firewall rules to reject oversized pingAddr parameters and monitor device logs for abnormal ping attempts.

Generated by OpenCVE AI on April 17, 2026 at 16:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 23 Feb 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 23 Feb 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Tenda hg9 Firmware
CPEs cpe:2.3:h:tenda:hg9:-:*:*:*:*:*:*:*
cpe:2.3:o:tenda:hg9_firmware:300001138:*:*:*:*:*:*:*
Vendors & Products Tenda hg9 Firmware

Mon, 23 Feb 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Tenda
Tenda hg9
Vendors & Products Tenda
Tenda hg9

Sun, 22 Feb 2026 02:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in Tenda HG9 300001138. This affects an unknown part of the file /boaform/formPing of the component Diagnostic Ping Endpoint. Performing a manipulation of the argument pingAddr results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Title Tenda HG9 Diagnostic Ping Endpoint formPing stack-based overflow
Weaknesses CWE-119
CWE-121
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-02-23T19:18:40.226Z

Reserved: 2026-02-20T20:14:48.904Z

Link: CVE-2026-2909

cve-icon Vulnrichment

Updated: 2026-02-23T19:18:35.379Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-22T02:16:58.100

Modified: 2026-02-23T20:21:38.593

Link: CVE-2026-2909

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-17T16:45:15Z

Weaknesses