CVE-2026-2140Disclosure(tenda / tx9)

LOWCVSS 7.4 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch tenda tx9 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was identified in Tenda TX9 up to 22.03.02.10_multi. Affected by this issue is the function sub_4223E0 of the file /goform/setMacFilterCfg. Such manipulation of the argument deviceList leads to buffer overflow. The attack may be launched remotely. The exploit is publicly available and might be used.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-120

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tx9
  • tx9_firmware

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Exploit: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-02-08); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
tx9tx9_firmware

1 version affected across 2 products

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-02-08: 4Mentions · 2026-02-13: 1PoC Mentioned / Linked · 2026-02-08: 1Patch / Workaround · 2026-02-08: 2Technical Details · 2026-02-08: 2Technical Details · 2026-02-13: 102-0802-13
Signal classification3 categories
Disclosure
360.0%
Exploit
120.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-084
Disclosure2Exploit1Patch1
2026-02-131
Disclosure1
Full discourse5 posts
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-2140 - Tenda - TX9 - https://www.redpacketsecurity.com/cve-alert-cve-2026-2140-tenda-tx9/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-2140 #tenda #tx9

    Post summary

    The post announces a CVE alert for Tenda TX9 (CVE‑2026‑2140) and links to an external site for details, without providing PoC, exploit code, or patch information.

    00011157
    3.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2140 A vulnerability was identified in Tenda TX9 up to 22.03.02.10_multi. Affected by this issue is the function sub_4223E0 of the file /goform/setMacFilterCfg. Such manipul… https://www.cve.org/CVERecord?id=CVE-2026-2140

    Post summary

    The post announces CVE-2026-2140, detailing its presence in Tenda TX9 firmware up to version 22.03.02.10_multi, specifically affecting the sub_4223E0 function in /goform/setMacFilterCfg, with no evidence of exploitation, PoC, or patch information.

    00010293
    56.5K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-2140 (CVSS:7.4, HIGH) is Analyzed. A vulnerability was identified in Tenda TX9 up to 22.03.02.10_multi. Affected by this issue is the function sub_4223E0 o..https://nvd.nist.gov/vuln/detail/CVE-2026-2140 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The text announces CVE-2026-2140 with its CVSS score and affected device details, but provides no PoC, exploit, or patch information.

    0000035
    171 followersView on X
  • transilienceai@transilienceai
    Patch

    @Shashwat_12304 🔴 NEW CVEs: • CVE-2026-2140/2139/2138 — Tenda TX9 routers • CVE-2026-2137 — Tenda TX3 routers • CVE-2026-1484/1485/1489 — Fedora mingw-glib2 • Cisco & F5 high-severity patches released Patch. Now.

    Post summary

    The message announces that patches for the listed CVEs (including Tenda routers and Fedora components) have been released and urges immediate action.

    0000080
    315 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Exploit

    🚨 High-severity buffer overflow in Tenda TX9 routers (up to v22.03.02.10_multi) risks remote code execution! Public exploit available — restrict remote access & monitor now. Patch ASAP. https://radar.offseq.com/threat/cve-2026-2140-buffer-overflow-in-tenda-tx9-09ab607e #OffSeq... https://t.co/RJL4TqJvHx

    Post summary

    A high‑severity buffer overflow in Tenda TX9 routers allows remote code execution; a public exploit is available and an urgent patch is recommended.

    0000043
    268 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendatx9---
OStendatx9_firmware---

Explore more