CVE-2026-2905

A vulnerability was identified in Tenda HG9 300001138. This impacts an unknown function of the file /boaform/formWlanSetup of the component Wireless Configuration Endpoint. The manipulation of the argument ssid leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit is publicly available and might be used.
References
Link Resource
https://github.com/QIU-DIE/cve-nneeww/issues/7 Exploit Issue Tracking Mitigation Third Party Advisory
https://vuldb.com/?ctiid.347214 Permissions Required VDB Entry
https://vuldb.com/?id.347214 Third Party Advisory VDB Entry
https://vuldb.com/?submit.755167 Third Party Advisory VDB Entry
https://www.tenda.com.cn/ Product
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tenda:hg9_firmware:300001138:*:*:*:*:*:*:*
cpe:2.3:h:tenda:hg9:-:*:*:*:*:*:*:*

History

17 Jun 2026, 10:32

Type Values Removed Values Added
Summary
  • (es) Se identificó una vulnerabilidad en Tenda HG9 300001138 que afecta a una función desconocida del archivo /boaform/formWlanSetup del componente Wireless Configuration Endpoint. Si se manipula el argumento ssid se puede provocar un desbordamiento de búfer basado en pila. El ataque puede iniciarse de forma remota. El exploit está disponible públicamente y podría ser utilizado.

23 Feb 2026, 20:22

Type Values Removed Values Added
CPE cpe:2.3:h:tenda:hg9:-:*:*:*:*:*:*:*
cpe:2.3:o:tenda:hg9_firmware:300001138:*:*:*:*:*:*:*
References () https://github.com/QIU-DIE/cve-nneeww/issues/7 - () https://github.com/QIU-DIE/cve-nneeww/issues/7 - Exploit, Issue Tracking, Mitigation, Third Party Advisory
References () https://vuldb.com/?ctiid.347214 - () https://vuldb.com/?ctiid.347214 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.347214 - () https://vuldb.com/?id.347214 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.755167 - () https://vuldb.com/?submit.755167 - Third Party Advisory, VDB Entry
References () https://www.tenda.com.cn/ - () https://www.tenda.com.cn/ - Product
First Time Tenda
Tenda hg9 Firmware
Tenda hg9

22 Feb 2026, 02:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-22 02:16

Updated : 2026-06-17 10:32


NVD link : CVE-2026-2905

Mitre link : CVE-2026-2905

CVE.ORG link : CVE-2026-2905


JSON object : View

Products Affected

tenda

  • hg9_firmware
  • hg9
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-121

Stack-based Buffer Overflow