CVE-2026-4490Disclosure

LOWCVSS 7.4 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A flaw has been found in Tenda A18 Pro 02.03.02.28. This issue affects the function setSchedWifi of the file /goform/openSchedWifi. This manipulation causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-03-22)
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-20: 1Mentions · 2026-03-21: 1Mentions · 2026-03-22: 2PoC Mentioned / Linked · 2026-03-20: 1Technical Details · 2026-03-20: 1Technical Details · 2026-03-22: 203-2003-2103-22
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-201
Disclosure1
2026-03-211
Disclosure1
2026-03-222
Disclosure2
Full discourse4 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-4490 A flaw has been found in Tenda A18 Pro 02.03.02.28. This issue affects the function setSchedWifi of the file /goform/openSchedWifi. This manipulation causes stack-based… https://www.cve.org/CVERecord?id=CVE-2026-4490 ----- Traducción: CVE-2026-4490 Se … http://infoflow.cloud`

    Post summary

    A stack‑based flaw in the Tenda A18 Pro’s setSchedWifi function is disclosed with specific function and file references, but no PoC, exploit, patch, or active exploitation details are provided.

    000007
    61 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4490 A flaw has been found in Tenda A18 Pro 02.03.02.28. This issue affects the function setSchedWifi of the file /goform/openSchedWifi. This manipulation causes stack-based… https://www.cve.org/CVERecord?id=CVE-2026-4490

    Post summary

    A stack-based vulnerability affecting Tenda A18 Pro's setSchedWifi function has been identified as CVE-2026-4490.

    0000085
    56.8K followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-4490 - Tenda - A18 Pro - https://www.redpacketsecurity.com/cve-alert-cve-2026-4490-tenda-a18-pro/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-4490 #tenda #a18-pro

    Post summary

    The tweet announces a CVE alert and links to an external site but contains no substantive details about the vulnerability, its exploitation, or mitigation.

    0000072
    3.6K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-4490: HIGH] Cybersecurity alert: Tenda A18 Pro 02.03.02.28 is vulnerable to remote stack-based buffer overflow due to a flaw in setSchedWifi function. Exploit published.#cve,CVE-2026-4490,#cybersecurity https://cvefind.com/CVE-2026-4490

    Post summary

    A new buffer‑overflow vulnerability (CVE‑2026‑4490) has been disclosed for Tenda A18 Pro firmware 02.03.02.28, and an exploit has reportedly been published, but no active exploitation or patch details are provided.

    0000047
    604 followersView on X

Explore more