CVE-2026-2930 MEDIUM

CVE-2026-2930: Tenda A18 Httpd Service UploadCfg webCgiGetUploadFile stack-based overflow

Vendor Tenda
Product A18
Weakness CWE-121
Published February 22, 2026
Last update February 27, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

What the vulnerability does

01Description

A vulnerability was identified in Tenda A18 15.13.07.13. The affected element is the function webCgiGetUploadFile of the file /cgi-bin/UploadCfg of the component Httpd Service. Such manipulation of the argument boundary leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used.

Key dates

02Disclosure timeline

February 22, 2026 CVE published
February 27, 2026 Record updated