PatchSiren cyber security CVE debrief
CVE-2026-5567 Tenda CVE debrief
A buffer overflow vulnerability has been identified in Tenda M3 1.0.0.10, specifically in the setAdvPolicyData function of the /goform/setAdvPolicyData component. This issue allows remote attackers to execute arbitrary code by manipulating the policyType argument. The vulnerability has a CVSS score of 7.4, indicating high severity. Evidence suggests that an exploit for this vulnerability has been published and may be used. Organizations using the affected product should prioritize patching or applying compensating controls. The vulnerability is classified under CWE-119 and CWE-120, indicating improper handling of memory and potential for remote code execution.
- Vendor
- Tenda
- Product
- M3
- CVSS
- HIGH 7.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-05
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-05
- Advisory updated
- 2026-07-24
Who should care
Network administrators and security teams responsible for Tenda M3 devices, particularly those using version 1.0.0.10, should be aware of this vulnerability and take immediate action to mitigate potential risks. IT teams managing network infrastructure, cybersecurity professionals, and incident response teams should prioritize remediation efforts and monitor for potential exploitation attempts.
Technical summary
The vulnerability is caused by a buffer overflow in the setAdvPolicyData function of the /goform/setAdvPolicyData component. This can be exploited remotely by manipulating the policyType argument. The CVSS score for this vulnerability is 7.4, indicating a high severity level. The vulnerability is classified under CWE-119 and CWE-120. Affected product deployments should be identified and prioritized for patching or mitigation. The exploit has been published, increasing the urgency for remediation.
Defensive priority
High
Recommended defensive actions
- Apply patches or updates provided by the vendor as soon as possible
- Implement compensating controls such as network segmentation or access restrictions
- Monitor for suspicious activity related to the affected component
- Conduct regular vulnerability assessments and penetration testing
- Consider implementing a web application firewall (WAF) to detect and prevent attacks
- Review and update incident response plans to include procedures for handling potential exploitation attempts
- Perform a thorough review of network logs and system activity to detect any signs of exploitation
Evidence notes
The CVE record was published on 2026-04-05T13:17:14.707Z and was last modified on 2026-07-24T09:10:00.153Z. The NVD entry is currently Analyzed. The vulnerability has been publicly disclosed and an exploit has been published. Evidence suggests that the vulnerability affects Tenda M3 version 1.0.0.10. However, the exact scope of affected deployments and potential impact is not fully clear. Defenders should verify the presence of affected products in their environments and prioritize remediation efforts.
Official resources
-
CVE-2026-5567 CVE record
CVE.org
-
CVE-2026-5567 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Exploit, Third Party Advisory
-
Mitigation or vendor reference
[email protected] - Third Party Advisory, VDB Entry
-
Mitigation or vendor reference
[email protected] - Third Party Advisory, VDB Entry
-
Source reference
[email protected] - Permissions Required, VDB Entry
-
Source reference
[email protected] - Product
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-05T13:17:14.707Z and has not been modified since then. The NVD entry is currently Analyzed.