CVE-2026-2191: Tenda AC9 formGetDdosDefenceList stack-based overflow
A weakness has been identified in Tenda AC9 15.03.06.42multi. Affected is the function formGetDdosDefenceList. This manipulation of the argument security.ddos.map causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2191?
CVE-2026-2191 has been classified as a critical severity vulnerability due to the potential for remote exploitation and stack-based buffer overflow.
How do I fix CVE-2026-2191?
To fix CVE-2026-2191, it is recommended to update the Tenda AC9 firmware to the latest version provided by the vendor.
What systems are affected by CVE-2026-2191?
CVE-2026-2191 affects the Tenda AC9 version 15.03.06.42_multi router.
What type of vulnerability is CVE-2026-2191?
CVE-2026-2191 is a stack-based buffer overflow vulnerability occurring in the function formGetDdosDefenceList.
Can CVE-2026-2191 be exploited remotely?
Yes, CVE-2026-2191 can be exploited remotely, allowing an attacker to initiate attacks from a distance.