A weakness has been identified in Tenda A21 1.0.0.0. This affects the function set_device_name of the file /goform/SetOnlineDevName. This manipulation of the argument devName causes stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.
Published: 2026-02-21
CVSS: 9.0
CVSS Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C
Download Exploit for CVE-2026-2886 here:
Use Tor Browser to access .onion site.
https://sonitex.com/exploit-257-cve-2026-27849/
https://sonitex.com/exploit-270-cve-2026-27493/
https://sonitex.com/exploit-449-cve-2026-3204/