HIGH

CVE-2026-19792

Tenda G0 httpd web management interface module setPortMapping buffer overflow

CVSS v3

8.8

HIGH

EPSS Score

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

A security flaw has been discovered in Tenda G0 up to 20260625. Impacted is the function setPortMapping of the file /goform/module of the component httpd web management interface. Performing a manipulation of the argument portMappingServer/porMappingtInternal/portMappingExternal results in buffer overflow. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.

Technical details

CVSS v3 Vector
3.1
Published
8/14/2026
Last Modified
8/14/2026

Frequently asked questions

What is CVE-2026-19792?

A security flaw has been discovered in Tenda G0 up to 20260625. Impacted is the function setPortMapping of the file /goform/module of the component httpd web management interface. Performing a manipulation of the argument portMappingServer/porMappingtInternal/portMappingExternal results in buffer overflow. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.

Is CVE-2026-19792 actively exploited?

Active exploitation of CVE-2026-19792 has not been confirmed. The EPSS score is N/A%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-19792?

CVE-2026-19792 has a CVSS v3 base score of 8.8 (HIGH severity), with vector string 3.1.

Is CVE-2026-19792 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.