PatchSiren cyber security CVE debrief
CVE-2026-5567 Tenda CVE debrief
A buffer overflow vulnerability has been identified in Tenda M3 1.0.0.10, specifically in the setAdvPolicyData function of the /goform/setAdvPolicyData component. This issue allows remote attackers to execute arbitrary code by manipulating the policyType argument. The vulnerability has a CVSS score of 7.4, indicating high severity. Evidence suggests that an exploit for this vulnerability has been published and may be used. Organizations using the affected product should prioritize patching or applying compensating controls. The vulnerability is classified under CWE-119 and CWE-120, indicating improper handling of memory and potential for remote code execution.
- Vendor
- Tenda
- Product
- M3
- CVSS
- HIGH 7.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-05
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-05
- Advisory updated
- 2026-07-24
Who should care
Network administrators and security teams responsible for Tenda M3 devices, particularly those using version 1.0.0.10, should be aware of this vulnerability and take immediate action to mitigate potential risks. IT teams managing network infrastructure, cybersecurity professionals, and incident response teams should prioritize remediation efforts and monitor for potential exploitation attempts.
Technical summary
The vulnerability is caused by a buffer overflow in the setAdvPolicyData function of the /goform/setAdvPolicyData component. This can be exploited remotely by manipulating the policyType argument. The CVSS score for this vulnerability is 7.4, indicating a high severity level. The vulnerability is classified under CWE-119 and CWE-120. Affected product deployments should be identified and prioritized for patching or mitigation. The exploit has been published, increasing the urgency for remediation.
Defensive priority
High
Recommended defensive actions
- Apply patches or updates provided by the vendor as soon as possible
- Implement compensating controls such as network segmentation or access restrictions
- Monitor for suspicious activity related to the affected component
- Conduct regular vulnerability assessments and penetration testing
- Consider implementing a web application firewall (WAF) to detect and prevent attacks
- Review and update incident response plans to include procedures for handling potential exploitation attempts
- Perform a thorough review of network logs and system activity to detect any signs of exploitation
Evidence notes
The CVE record was published on 2026-04-05T13:17:14.707Z and was last modified on 2026-07-24T09:10:00.153Z. The NVD entry is currently Analyzed. The vulnerability has been publicly disclosed and an exploit has been published. Evidence suggests that the vulnerability affects Tenda M3 version 1.0.0.10. However, the exact scope of affected deployments and potential impact is not fully clear. Defenders should verify the presence of affected products in their environments and prioritize remediation efforts.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-5567 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-5567
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-5567 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-5567
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/Moxxkidd/CVE/issues/2
[email protected] - Exploit, Third Party Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://vuldb.com/submit/782999
[email protected] - Third Party Advisory, VDB Entry
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://vuldb.com/vuln/355337
[email protected] - Third Party Advisory, VDB Entry
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/355337/cti
[email protected] - Permissions Required, VDB Entry
-
Source reference
Unverified legacy reference
URL: https://www.tenda.com.cn/
[email protected] - Product
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.