CVE-2026-4491Disclosure

LOWCVSS 7.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been found in Tenda A18 Pro 02.03.02.28. Impacted is the function fromSetIpMacBind of the file /goform/SetIpMacBind. Such manipulation of the argument list leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-03-20); latest day: 1
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-03-20: 3Mentions · 2026-03-21: 1Mentions · 2026-03-22: 1Technical Details · 2026-03-20: 3Technical Details · 2026-03-22: 103-2003-2103-22
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-203
Disclosure3
2026-03-211
General1
2026-03-221
Disclosure1
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-4491 A vulnerability has been found in Tenda A18 Pro 02.03.02.28. Impacted is the function fromSetIpMacBind of the file /goform/SetIpMacBind. Such manipulation of the argume… https://www.cve.org/CVERecord?id=CVE-2026-4491

    Post summary

    CVE-2026-4491, a vulnerability in the Tenda A18 Pro firmware affecting the fromSetIpMacBind function, has been announced with technical details, but no PoC, exploit, patch, or evidence of active exploitation is reported.

    0000089
    56.8K followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-4491 - Tenda - A18 Pro - https://www.redpacketsecurity.com/cve-alert-cve-2026-4491-tenda-a18-pro/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-4491 #tenda #a18-pro

    Post summary

    The tweet announces CVE‑2026‑4491 affecting Tenda A18 Pro, linking to an external page, but it provides no detailed technical, exploit, or mitigation information.

    0000087
    3.6K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4491 - Tenda A18 Pro SetIpMacBind fromSetIpMacBind stack-based overflow Intel Report: https://ift.tt/pdbyI04

    Post summary

    The tweet announces CVE-2026-4491, identifying a stack‑based overflow in Tenda A18 Pro, and references an Intel report.

    0000044
    334 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4491 Tenda A18 Pro Remote Stack-Based Buffer Overflow in SetIpMacBind Function https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4491

    Post summary

    The text reports a new CVE describing a remote stack-based buffer overflow in Tenda A18 Pro, without mentioning PoC, exploitation tools, or patches.

    0000043
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-4491: HIGH] Critical cyber security alert: Tenda A18 Pro 02.03.02.28 vulnerable to remote stack-based buffer overflow attack through fromSetIpMacBind function. Take precautions now.#cve,CVE-2026-4491,#cybersecurity https://cvefind.com/CVE-2026-4491

    Post summary

    This alert reports the discovery of a stack‑based buffer overflow vulnerability (CVE‑2026‑4491) in Tenda A18 Pro firmware 02.03.02.28, advising users to take precautions.

    0000069
    604 followersView on X

Explore more