CVE-2026-2909Disclosure(tenda / hg9)

MEDIUMCVSS 7.4 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch tenda hg9 systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability was detected in Tenda HG9 300001138. This affects an unknown part of the file /boaform/formPing of the component Diagnostic Ping Endpoint. Performing a manipulation of the argument pingAddr results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • hg9
  • hg9_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-02-22); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
hg9hg9_firmware

2 versions affected across 2 products

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-22: 1Mentions · 2026-02-27: 1Mentions · 2026-05-07: 1Active Exploitation · 2026-05-07: 1Patch / Workaround · 2026-05-07: 1Technical Details · 2026-02-27: 1Technical Details · 2026-05-07: 102-2202-2705-07
Signal classification2 categories
Disclosure
266.7%
Active Exploitation
133.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-02-221
Disclosure1
2026-02-271
Disclosure1
2026-05-071
Active Exploitation1
Full discourse3 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-2909 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-2909 #CVE-2026-2909 #CVE #High #CyberSecurity #InfoSec https://t.co/Mdjvii4BsN

    Post summary

    A new CVE-2026-2909 with severity 8.8 and high risk level is announced, affecting multiple unspecified products.

    1000043
    57 followersView on X
  • boarnet@boarnetio
    Active Exploitation

    ⚠️ CRITICAL VULNERABILITY ALERT ⚠️ Botnets are actively exploiting unpatched IoT devices Affected: Tenda, D-Link, & generic routers. CVEs: CVE-2026-1689: Root RCE via Login CVE-2026-2909: Buffer Overflow Patch firmware & disable WAN management! 🛡️ #InfoSec #IoT #RCE

    Post summary

    A warning that Tenda, D‑Link, and generic routers are vulnerable to CVE‑2026‑1689 (root RCE) and CVE‑2026‑2909 (buffer overflow), both being actively exploited by botnets, with a recommendation to patch firmware and disable WAN management.

    000000
    1 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-2909 (CVSS:7.4, HIGH) is Analyzed. A vulnerability was detected in Tenda HG9 300001138. This affects an unknown part of the file /boaform/formPing of the c..https://nvd.nist.gov/vuln/detail/CVE-2026-2909 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The text announces CVE‑2026‑2909 with a CVSS of 7.4, affecting the /boaform/formPing file on Tenda HG9 devices.

    0000016
    173 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendahg9---
OStendahg9_firmware300001138--

Explore more