CVE-2026-2191General(tenda / ac9)

LOWCVSS 7.3 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch tenda ac9 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A weakness has been identified in Tenda AC9 15.03.06.42_multi. Affected is the function formGetDdosDefenceList. This manipulation of the argument security.ddos.map causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ac9
  • ac9_firmware

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Exploit: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-08); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
ac9ac9_firmware

2 versions affected across 2 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-08: 1Mentions · 2026-02-09: 1PoC Mentioned / Linked · 2026-02-09: 1Patch / Workaround · 2026-02-09: 1Technical Details · 2026-02-09: 102-0802-09
Signal classification2 categories
General
150.0%
Exploit
150.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-081
General1
2026-02-091
Exploit1
Full discourse2 posts
  • CVE@CVEnew
    General

    CVE-2026-2191 A weakness has been identified in Tenda AC9 15.03.06.42_multi. Affected is the function formGetDdosDefenceList. This manipulation of the argument http://security.ddos.map caus… https://www.cve.org/CVERecord?id=CVE-2026-2191

    Post summary

    A weakness in Tenda AC9 firmware affecting the formGetDdosDefenceList function is reported, but no PoC, exploit details, mitigation steps, or evidence of active exploitation are provided.

    00010264
    56.5K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Exploit

    🚨 HIGH-severity alert: Tenda AC9 routers (v15.03.06.42_multi) have a stack overflow flaw allowing remote code execution. Public exploit is out — limit exposure, segment networks, and disable remote admin! 🔒 https://radar.offseq.com/threat/cve-2026-2191-stack-based-buffer-overf... https://t.co/ZR9S3fMgoh

    Post summary

    High‑severity stack‑overflow vulnerability in Tenda AC9 routers permits remote code execution; a public exploit is available, prompting network segmentation and disabling remote admin as mitigations.

    0000051
    268 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendaac9---
OStendaac9_firmware15.03.06.42_multi--

Explore more