CVE-2026-8138Disclosure(tenda / cx12l)

LOWCVSS 7.4 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for tenda cx12l systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability was found in Tenda CX12L 16.03.53.12. This issue affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg”. The manipulation results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cx12l
  • cx12l_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-08); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
cx12lcx12l_firmware

2 versions affected across 2 products

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-08: 2Mentions · 2026-05-09: 1Active Exploitation · 2026-05-08: 1Technical Details · 2026-05-08: 2Technical Details · 2026-05-09: 105-0805-09
Signal classification2 categories
Disclosure
266.7%
Active Exploitation
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-082
Active Exploitation1Disclosure1
2026-05-091
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-8138 A vulnerability was found in Tenda CX12L 16.03.53.12. This issue affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg”. The manipulation results … https://www.cve.org/CVERecord?id=CVE-2026-8138

    Post summary

    The post announces CVE-2026-8138 in Tenda CX12L firmware, highlighting the affected formSetPPTPServer function without providing any PoC, exploit, or patch details.

    00010167
    57.5K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Active Exploitation

    ⚠️ HIGH — CVE-2026-8138 A vulnerability was found in Tenda CX12L 16.03.53.12. This issue affects the function formSetPPTPServer of the file /go… CVSS 8.8 ⚡ Exploit in the wild Full analysis → https://sec.kaitan.id/cves/CVE-2026-8138 #Tenda #CyberSecurity #InfoSec

    Post summary

    CVE‑2026‑8138, a high‑severity flaw in Tenda CX12L’s formSetPPTPServer, is being actively exploited in the wild.

    0000053
    516 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-8138 Stack-Based Buffer Overflow in Tenda CX12L 16.03.53.12 PPT... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-8138 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet announces CVE-2026‑8138, noting a stack-based buffer overflow in a Tenda CX12L router firmware, and links to a vulnerability details page, but includes no PoC, exploit, or remediation information.

    0000029
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendacx12l---
OStendacx12l_firmware16.03.53.12--

Explore more