CVE List

CVE-2026-2138

Critical 8.8

A vulnerability was found in Tenda TX9 up to 22.03.02.10_multi. Affected is the function sub_42D03C of the file /goform/SetStaticRouteCfg. The manipulation of the argument list results in buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used.

Published February 8, 2026.

Affected software

Get alerts for Tenda Tx9 Firmware

Reference links