HIGH 8.5 NVD
CVE-2026-104611
A vulnerability was detected in Tenda AC9 15.03.02.13. Affected is an unknown function of the file /goform/fast_setting_internet_set of the component POST Reque
A vulnerability was detected in Tenda AC9 15.03.02.13. Affected is an unknown function of the file /goform/fast_setting_internet_set of the component POST Request Handler. Performing a manipulation of the argument netWanType results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.
References
- https://github.com/ZaneBoden/CVEs/blob/main/Tenda-AC9-fast_setting_internet_set.md
- https://vuldb.com/cve/CVE-2026-104611
- https://vuldb.com/submit/962720
- https://vuldb.com/vuln/412918
- https://vuldb.com/vuln/412918/cti
This high severity vulnerability with a CVSS score of 8.5 was published on 2026-10-02 via NVD.
vulnfeed aggregates 10476 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.