CVE-2026-19792Disclosure

MEDIUMCVSS 7.4 · HIGH

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A security flaw has been discovered in Tenda G0 up to 20260625. Impacted is the function setPortMapping of the file /goform/module of the component httpd web management interface. Performing a manipulation of the argument portMappingServer/porMappingtInternal/portMappingExternal results in buffer overflow. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-120

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-08-14); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-08-14: 3Mentions · 2026-08-15: 1Active Exploitation · 2026-08-14: 1Patch / Workaround · 2026-08-15: 1Technical Details · 2026-08-14: 2Technical Details · 2026-08-15: 108-1408-15
Signal classification2 categories
Disclosure
375.0%
Active Exploitation
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-08-143
Active Exploitation1Disclosure2
2026-08-151
Disclosure1
Full discourse4 posts
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    CVE-2026-19792 – Critical buffer overflow in Tenda G0 httpd via setPortMapping. Remote RCE risk. CVSS 8.8. Exploit public, no patch yet. Disable access or update ASAP. #CVE #Tenda #infosec https://www.valtersit.com/cve/CVE-2026-19792 #CVE #infosec #SysAdmin #cybersecurity #Linux #infosec #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu #debian #ukraine #spain #ireland #unitedkingdom #canada #finland #estonia #lithuania #ireland #hungary #denmark #norway #malta

    Post summary

    The post announces a critical buffer overflow in Tenda G0, notes a publicly available exploit but no patch yet, and recommends disabling access until an update is applied.

    0000058
    1.0K followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Attention, elevated activities detected targeting Tenda G0 (CVE-2026-19792) https://vuldb.com/vuln/389758/cti

    Post summary

    The note alerts to elevated activity targeting Tenda G0 via CVE‑2026‑19792, indicating potential in‑the‑wild exploitation, but provides no patch, PoC, or technical details.

    00000100
    2.3K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-19792 A security flaw has been discovered in Tenda G0 up to 20260625. Impacted is the function setPortMapping of the file /goform/module of the component httpd web manageme… https://www.cve.org/CVERecord?id=CVE-2026-19792 ----- Traducción: CVE-2026-19792 Se … https://infoflow.cloud`

    Post summary

    A new CVE (CVE-2026-19792) affecting Tenda G0 releases up to 2026‑06‑25 has been identified, impacting the setPortMapping function in the HTTPD web management module, with a link to the official CVE record.

    0000029
    98 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-19792 A security flaw has been discovered in Tenda G0 up to 20260625. Impacted is the function setPortMapping of the file /goform/module of the component httpd web manageme… https://www.cve.org/CVERecord?id=CVE-2026-19792

    Post summary

    A new vulnerability (CVE-2026-19792) affecting Tenda G0's HTTPD web management setPortMapping function has been identified; no PoC, exploit, or patch details are included.

    00000977
    57.9K followersView on X

Explore more