CVE-2026-4492Disclosure

LOWCVSS 7.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was found in Tenda A18 Pro 02.03.02.28. The affected element is the function set_qosMib_list of the file /goform/formSetQosBand. Performing a manipulation of the argument list results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been made public and could be used.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Exploit: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-20); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-20: 1Mentions · 2026-03-21: 1Mentions · 2026-03-22: 1Technical Details · 2026-03-20: 1Technical Details · 2026-03-22: 103-2003-2103-22
Signal classification2 categories
Disclosure
266.7%
Exploit
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-201
Exploit1
2026-03-211
Disclosure1
2026-03-221
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-4492 A vulnerability was found in Tenda A18 Pro 02.03.02.28. The affected element is the function set_qosMib_list of the file /goform/formSetQosBand. Performing a manipulati… https://www.cve.org/CVERecord?id=CVE-2026-4492

    Post summary

    The post discloses a vulnerability in Tenda A18 Pro firmware, detailing the affected function and file, but does not mention PoC, exploitation, patches, or debunking.

    0000087
    56.8K followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-4492 - Tenda - A18 Pro - https://www.redpacketsecurity.com/cve-alert-cve-2026-4492-tenda-a18-pro/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-4492 #tenda #a18-pro

    Post summary

    The post announces CVE-2026-4492 for the Tenda A18 Pro and links to a security advisory, but no further technical, exploit, or mitigation details are provided.

    0000076
    3.6K followersView on X
  • CVEFind.com@CveFindCom
    Exploit

    [CVE-2026-4492: HIGH] Critical vulnerability discovered in Tenda A18 Pro 02.03.02.28 allows remote attackers to trigger a stack-based buffer overflow. Public exploit available. #cybersecurity#cve,CVE-2026-4492,#cybersecurity https://cvefind.com/CVE-2026-4492

    Post summary

    The post announces a stack-based buffer overflow (CVE-2026-4492) in Tenda A18 Pro, notes a publicly available exploit, and provides technical details but no patch or active exploitation claim.

    0000054
    604 followersView on X

Explore more