CVE-2026-2192Disclosure(tenda / ac9)

LOWCVSS 7.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch tenda ac9 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A security vulnerability has been detected in Tenda AC9 15.03.06.42_multi. Affected by this vulnerability is the function formGetRebootTimer. Such manipulation of the argument sys.schedulereboot.start_time/sys.schedulereboot.end_time leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ac9
  • ac9_firmware

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-08); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
ac9ac9_firmware

2 versions affected across 2 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-08: 1Mentions · 2026-02-09: 1Patch / Workaround · 2026-02-09: 1Technical Details · 2026-02-08: 1Technical Details · 2026-02-09: 102-0802-09
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-081
Disclosure1
2026-02-091
Patch1
Full discourse2 posts
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    ⚠️ HIGH severity: CVE-2026-2192 stack-based buffer overflow in Tenda AC9 routers (15.03.06.42_multi). Remote code execution risk for privileged users! Patch ASAP or restrict access. More details: https://radar.offseq.com/threat/cve-2026-2192-stack-based-buffer-overflow-in-tend... https://t.co/PWHGnxxp88

    Post summary

    The tweet announces a high‑severity stack‑based buffer overflow in Tenda AC9 routers that can lead to remote code execution and urges immediate patching or access restriction.

    0100055
    268 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2192 A security vulnerability has been detected in Tenda AC9 15.03.06.42_multi. Affected by this vulnerability is the function formGetRebootTimer. Such manipulation of the a… https://www.cve.org/CVERecord?id=CVE-2026-2192

    Post summary

    A CVE-2026-2192 vulnerability was identified in Tenda AC9 firmware affecting the formGetRebootTimer function, with no evidence of exploitation or patch information provided.

    00010315
    56.5K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendaac9---
OStendaac9_firmware5.03.06.42_multi--

Explore more