What is CVE-2026-19791?
A stack-based buffer overflow vulnerability was identified in the `addStaticRoute` function of the httpd web management interface on Tenda G0 devices up to version 20260625. Manipulating the `staticRouteNet` argument can allow remote code execution. It is recommended to update the device firmware to the latest version.
Azərbaycanca: Tenda G0 cihazının 20260625-ci ilə qədərki versiyalarında httpd idarəetmə interfeysindəki `addStaticRoute` funksiyasında stack-based buffer overflow zəifliyi aşkarlanıb. `staticRouteNet` arqumentinin manipulyasiyası uzaqdan kod icrasına imkan verə bilər. Cihaz proqram təminatının ən son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119; shared vendor: Tenda
FAQ2
In which function of the Tenda G0 device was CVE-2026-19791 identified?
This vulnerability is a stack-based buffer overflow identified in the `addStaticRoute` function of the device's httpd web management interface.
What is recommended for Tenda G0 users to protect against CVE-2026-19791?
Users are recommended to update the device firmware to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.