A weakness has been identified in Tenda G0 up to 20260625. The affected element is the function addStaticRoute of the file /goform/module of the component httpd web management interface. Executing a manipulation of the argument staticRouteNet can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.
Command Injection in Tenda G0 routers with firmware versions v15.11.0.6(9039)CN and v15.11.0.5(5876)CN , and Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)CN or v15.11.0.16(9024)CN allows remote attackers to execute arbitrary OS commands via a crafted action/setDebugCfg request. This occurs because the "formSetDebugCfg" function executes glibc's system function with untrusted input.