CVE detail
CVE-2026-2874
A flaw has been found in Tenda A21 1.0.0.0. Impacted is the function form_fast_setting_wifi_set of the file /goform/fast_setting_wifi_set. Executing a manipulation of the argument ssid can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been published and may be used.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 17.9 · diversity 11.5 · KEV 0.0 · OTX 0.0 · PoC 4.5
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
5 source links · newest first
- https://www.tenda.com.cn/www.tenda.com.cn
No excerpt available.
Third Party Advisorywww.tenda.com.cnFeb 21, 2026, 6:15 PM - https://vuldb.com/?submit.754636vuldb.com
No excerpt available.
Exploitvuldb.comFeb 21, 2026, 6:15 PM - https://vuldb.com/?id.347111vuldb.com
No excerpt available.
Exploitvuldb.comFeb 21, 2026, 6:15 PM - https://vuldb.com/?ctiid.347111vuldb.com
No excerpt available.
Exploitvuldb.comFeb 21, 2026, 6:15 PM No excerpt available.
Exploitgithub.comFeb 21, 2026, 6:15 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
1 repository references · best confidence 0.90 · max 0 stars
- QIU-DIE/cve-nneewwHigh confidencegithubNVD Exploit reference0 starsDiscovered Jul 11, 2026, 3:20 AM
NVD labels the source link as Exploit; this is not independent verification of the repository's code.
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-2886CVSS 7.4 · High
A weakness has been identified in Tenda A21 1.0.0.0. This affects the function set_device_name of the file /goform/SetOnlineDevName. This manipulation of the argument devName caus…
- CVE-2026-2873CVSS 7.4 · High
A vulnerability was detected in Tenda A21 1.0.0.0. This issue affects the function setSchedWifi of the file /goform/openSchedWifi. Performing a manipulation of the argument schedS…
- CVE-2026-2872CVSS 7.4 · High
A security vulnerability has been detected in Tenda A21 1.0.0.0. This vulnerability affects the function set_device_name of the file /goform/setBlackRule of the component MAC Filt…
- CVE-2026-2871CVSS 7.4 · High
A weakness has been identified in Tenda A21 1.0.0.0. This affects the function fromSetIpMacBind of the file /goform/SetIpMacBind. This manipulation of the argument list causes sta…
- CVE-2026-2870CVSS 7.4 · High
A security flaw has been discovered in Tenda A21 1.0.0.0. Affected by this issue is the function set_qosMib_list of the file /goform/formSetQosBand. The manipulation of the argume…
- CVE-2024-14042CVSS 2.1 · Low
A vulnerability was found in Open5GS up to 2.7.1. This affects the function hss_ogs_diam_s6a_air_cb/hss_ogs_diam_s6a_ulr_cb of the file src/hss/hss-s6a-path.c of the component Dia…