TopVuln

High-risk vulnerability digests

CVE-2026-8138

  • HIGH

Details

CVSS v3
8.8
CVSS v4
7.4
CVSS v2
9.0
NVD published
2026-05-08 05:16:11
EPSS
<0.1% probability · 14.3th percentile — 2026-05-11
Affected versions
Tenda CX12L 16.03.53.12
Summary
This is a remote stack-based buffer overflow vulnerability in Tenda CX12L consumer wireless routers. The flaw resides in the formSetPPTPServer function that handles PPTP server configuration. A remote attacker can trigger the overflow to execute arbitrary code with root privileges on the affected device.
Remediation
Check for the latest official firmware update from Tenda for the CX12L model and install available patches immediately. Disable the PPTP server functionality if it is not actively used, and restrict external access to the router's management interface to trusted IP addresses only.
Exploit info
This exploit has been publicly disclosed, with references to this issue documented in trusted public vulnerability databases. You may check Exploit-DB or GitHub for potential exploit details.

View on NVD

TopVuln sends digest emails with high-risk CVE picks across multiple authoritative sources—curated with EPSS and AI. Choose daily per-stream emails and optional weekly or monthly roundups.

Subscribe — free email digest or paid plan

Information is aggregated from multiple authoritative sources for convenience; verify with NVD and vendors before operational decisions.