CVE-2026-2137Disclosure(tenda / tx3)

LOWCVSS 7.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch tenda tx3 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been found in Tenda TX3 up to 16.03.13.11_multi. This impacts an unknown function of the file /goform/SetIpMacBind. The manipulation of the argument list leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-120

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tx3
  • tx3_firmware

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-02-08); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
tx3tx3_firmware

1 version affected across 2 products

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-02-08: 3Mentions · 2026-02-09: 1Mentions · 2026-02-13: 1Patch / Workaround · 2026-02-08: 1Technical Details · 2026-02-08: 1Technical Details · 2026-02-09: 1Technical Details · 2026-02-13: 102-0802-0902-13
Signal classification3 categories
Disclosure
360.0%
General
120.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-083
Disclosure1General1Patch1
2026-02-091
Disclosure1
2026-02-131
Disclosure1
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-2137 A vulnerability has been found in Tenda TX3 up to 16.03.13.11_multi. This impacts an unknown function of the file /goform/SetIpMacBind. The manipulation of the argument… https://www.cve.org/CVERecord?id=CVE-2026-2137

    Post summary

    The post announces the discovery of CVE-2026-2137 in Tenda TX3 firmware, noting its effect on the /goform/SetIpMacBind function, but does not provide a PoC, exploit, patch, or evidence of active exploitation.

    00010317
    56.5K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-2137 (CVSS:7.4, HIGH) is Analyzed. A vulnerability has been found in Tenda TX3 up to 16.03.13.11_multi. This impacts an unknown function of the file /gofor..https://nvd.nist.gov/vuln/detail/CVE-2026-2137 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    A new high‑severity vulnerability (CVE‑2026‑2137) affecting Tenda TX3 routers is disclosed, with CVSS 7.4 and an unknown function in the /gofor file highlighted; no exploit, patch, or active exploitation information is provided.

    0000034
    171 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-2137: HIGH] Critical vulnerability in Tenda TX3 up to 16.03.13.11_multi - exploit allows remote attacks through buffer overflow in /goform/SetIpMacBind. Take action immediately.#cve,CVE-2026-2137,#cybersecurity https://cvefind.com/CVE-2026-2137

    Post summary

    The post announces a high‑severity buffer‑overflow vulnerability (CVE‑2026‑2137) in Tenda TX3 routers up to firmware 16.03.13.11_multi that can be exploited remotely; no PoC, patch, or active exploitation is detailed.

    00000152
    583 followersView on X
  • transilienceai@transilienceai
    Patch

    @Shashwat_12304 🔴 NEW CVEs: • CVE-2026-2140/2139/2138 — Tenda TX9 routers • CVE-2026-2137 — Tenda TX3 routers • CVE-2026-1484/1485/1489 — Fedora mingw-glib2 • Cisco & F5 high-severity patches released Patch. Now.

    Post summary

    New CVEs announced for Tenda routers, Fedora mingw-glib2, and Cisco & F5; high‑severity patches have been released.

    0000080
    315 followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-2137 - Tenda - TX3 - https://www.redpacketsecurity.com/cve-alert-cve-2026-2137-tenda-tx3/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-2137 #tenda #tx3

    Post summary

    The post merely posts a link to a CVE alert with no further information.

    00000108
    3.5K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendatx3---
OStendatx3_firmware---

Explore more