CVE-2026-4567General(tenda / a15)

HIGHCVSS 8.9 · HIGH

Exploitation observed; activity peaked at 6 mentions and remains active

Immediate actions

  • Patch tenda a15 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability has been found in Tenda A15 15.13.07.13. The impacted element is the function UploadCfg of the file /cgi-bin/UploadCfg. The manipulation of the argument File leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • a15
  • a15_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 13 mentions across 6 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • General: 6 classified signals
  • Disclosure: 3 classified signals
  • Peaked 4d ago at 6 mentions (2026-03-23); latest day: 1
  • 13 total mentions across 6 days

Affected systems

Vendors
Products
a15a15_firmware

2 versions affected across 2 products

Deep dive

Activity timeline13 mentions / 6d
02356Mentions · 2026-03-22: 1Mentions · 2026-03-23: 6Mentions · 2026-03-24: 1Mentions · 2026-03-27: 1Mentions · 2026-03-28: 3Mentions · 2026-04-10: 1PoC Mentioned / Linked · 2026-03-23: 1Exploit Tool / Code · 2026-03-23: 1Active Exploitation · 2026-04-10: 1Patch / Workaround · 2026-03-23: 2Technical Details · 2026-03-23: 4Technical Details · 2026-03-28: 1Technical Details · 2026-04-10: 103-2203-2303-2403-2703-2804-10
Signal classification5 categories
General
646.2%
Disclosure
323.1%
Patch
215.4%
Exploit
17.7%
Active Exploitation
17.7%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-221
Disclosure1
2026-03-236
Disclosure1Exploit1General2Patch2
2026-03-241
Disclosure1
2026-03-271
General1
2026-03-283
General3
2026-04-101
Active Exploitation1
Full discourse13 posts
  • z3n@zench4n
    General

    Deep dive analysis in AI security means dissecting agent behavior, not just code. We're past simple CVE scans. Think beyond CVE-2026-4567's upload vuln; how does an agent's *decision-making process* introduce risk?

    Post summary

    The tweet merely references CVE‑2026‑4567’s upload vulnerability without providing additional technical depth, exploits, or mitigation information, thus serving as a general mention of the CVE.

    1000055
    1.4K followersView on X
  • z3n@zench4n
    General

    For agent systems, this means tracing decision pathways, data flow, and external API calls. Beyond CVEs like `CVE-2026-4567` (Tenda A15 upload), we look at how agent logic could be manipulated.

    Post summary

    The text merely references CVE-2026-4567 (Tenda A15 upload) without offering any practical, technical, or mitigation details.

    1000022
    1.4K followersView on X
  • z3n@zench4n
    General

    Recent CVEs highlight risks beyond traditional web apps. CVE-2026-4567 (Tenda A15 firmware) reminds us agent systems often interact with embedded devices, expanding the attack surface.

    Post summary

    The text only references the CVE identifier and a device model without further technical, exploit, or mitigation details.

    100000
    1.4K followersView on X
  • z3n@zench4n
    General

    Recent CVEs highlight risks beyond traditional web apps. CVE-2026-4567 (Tenda A15 firmware) reminds us agent systems often interact with embedded devices, expanding the attack surface.

    Post summary

    The post notes a CVE affecting Tenda A15 firmware, highlighting embedded device risks, but offers no additional details such as PoC, exploit, patch, or active usage.

    100005
    1.4K followersView on X
  • CTIWatch@ctiwatchcloud
    General

    🔍 Today's Top Vulnerabilities 🔴 CVE-2026-4606 | CVSS 10.0 🔴 CVE-2026-3587 | CVSS 10.0 🔴 CVE-2026-4567 | CVSS 9.8 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The post simply lists high‑scoring CVEs with a link to a vulnerability page, but provides no Proof of Concept, exploitation details, or mitigation info.

    0001071
    5.6K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-4567 — CVSS 9.8/10 ██████████ A vulnerability has been found in Tenda A15 15.13.07.13. The impacted element is the function UploadCfg of the file... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/62Jlq3sAfA

    Post summary

    A critical vulnerability (CVSS 9.8) in Tenda A15’s UploadCfg function has been disclosed, and a patch is available.

    1000047
    9 followersView on X
  • 0day Signal@0dayPublishing
    Exploit

    🚨 CVE-2026-4567: Tenda A15 UploadCfg stack-based o... Unauthenticated remote stack smash in Tenda A15's UploadCfg CGI - public exploit available for instant router takeover. ... https://zerodaysignal.com/vulnerability/CVE-2026-4567 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces a publicly available exploit for CVE-2026-4567 targeting a stack-based buffer overflow in the Tenda A15’s UploadCfg CGI, enabling instant router takeover without authentication.

    01000110
    162 followersView on X
  • RagingCISO@CisoRaging77913
    Active Exploitation

    CVE-2026-4567: LLM backdoor via data poisoning. Trigger phrase → exfil via DNS or RCE. Invisible to static scanners—it's in the weights. Llama, Mistral variants affected. npm/PyPI mistakes, now in model hubs. Your HR chatbot exfils data on magic words. AI-powered breach.

    Post summary

    CVE-2026-4567 describes a data‑poisoning backdoor in Llama and Mistral LLMs that triggers exfiltration via DNS or RCE, with evidence that the flaw is being abused by HR chatbots.

    0000059
    5 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-4567 📊 Severity: 9.8 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4567 #CVE-2026-4567 #CVE #Critical  #CyberSecurity #InfoSec https://t.co/GfWfmRqSA2

    Post summary

    The tweet announces a new high‑severity CVE with a link to the NVD entry, but provides no additional technical, exploit, or mitigation details.

    0000024
    111 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-4567 A vulnerability has been found in Tenda A15 15.13.07.13. The impacted element is the function UploadCfg of the file /cgi-bin/UploadCfg. The manipulation of the argument… https://www.cve.org/CVERecord?id=CVE-2026-4567

    Post summary

    The post briefly announces a new CVE affecting Tenda A15 with minimal detail and contains no evidence of exploitation, PoC, or patch information.

    0000093
    56.8K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4567 - Tenda A15 UploadCfg stack-based overflow Intel Report: https://ift.tt/7uKzaT5

    Post summary

    The tweet announces a new stack‑based overflow vulnerability (CVE-2026-4567) affecting the Tenda A15 via the UploadCfg interface, with no PoC, exploit, patch, or active exploitation details provided.

    0000028
    289 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-4567: CRITICAL] Warning: Vulnerability discovered in Tenda A15 15.13.07.13. Attackers can exploit stack-based buffer overflow remotely through UploadCfg function. Update needed to stay secure.#cve,CVE-2026-4567,#cybersecurity https://cvefind.com/CVE-2026-4567

    Post summary

    A critical stack‑based buffer overflow was found in Tenda A15 firmware (15.13.07.13), allowing remote exploitation via the UploadCfg function; users are advised to apply the necessary update to mitigate the risk.

    0000063
    605 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    The severity is increased for this new vulnerability affecting Tenda A15 (CVE-2026-4567) https://vuldb.com/?id.352404

    Post summary

    The tweet notes that a newly identified vulnerability in Tenda A15 (CVE-2026-4567) now has a higher severity rating, but provides no additional technical details or exploits.

    0000078
    2.1K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendaa15---
OStendaa15_firmware15.13.07.13--

Explore more