CVE-2026-2906 describes a high-severity stack-based buffer overflow vulnerability in the Samba Configuration Endpoint of Tenda HG9 300001138 firmware. This flaw, specifically within the /boaform/formSamba file when handling the "sambaCap" argument, allows for remote exploitation. With a CVSS score of 8.8 (High), successful exploitation could lead to high impact on confidentiality, integrity, and availability. While a public exploit exists, there is currently no evidence of active exploitation, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
300001138CPE matchmatch criteria | cpe:2.3:o:tenda:hg9_firmware:300001138:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.