CVE-2026-4567: Tenda a15 Firmware

Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.

A vulnerability has been found in Tenda A15 15.13.07.13. The impacted element is the function UploadCfg of the file /cgi-bin/UploadCfg. The manipulation of the argument File leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

Affected products

  • Tenda a15 Firmware: version 15.13.07.13 only

Published 2026-03-23. Last modified 2026-06-17.