What is CVE-2026-19790?
A stack-based buffer overflow vulnerability was identified in the formSetPortMirror function of the /goform/module file within the httpd Web Management Interface of Tenda G0 devices up to version 20260625. The issue is triggered by manipulating the portMirrorMirroredPorts argument. It is recommended to restrict access to the device's management interface to mitigate the risk.
Azərbaycanca: Tenda G0 cihazlarının 20260625-ə qədər versiyalarında, httpd Web İdarəetmə İnterfeysindəki /goform/module faylında yerləşən formSetPortMirror funksiyasında stack-based buffer overflow zəifliyi aşkar edilib. Bu zəiflik portMirrorMirroredPorts arqumentinin manipulyasiyası ilə istismar oluna bilər. Cihazın idarəetmə interfeysinə girişi məhdudlaşdırmaqla risk azaldıla bilər.
Related CVEs
link basis: same weakness class CWE-119; shared vendor: Tenda
FAQ2
Which argument's manipulation can exploit the stack-based buffer overflow vulnerability in the formSetPortMirror function of Tenda G0 devices?
The manipulation of the portMirrorMirroredPorts argument can exploit this vulnerability.
What primary measure is recommended to mitigate the impact of CVE-2026-19790?
It is recommended to restrict access to the device's management interface to mitigate the risk.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.