CVE-2026-105778: Tenda AC5 Wifi setWifi stack-based overflow
A vulnerability has been found in Tenda AC5 02.03.01.111multi. Affected by this issue is some unknown functionality of the file /goform/setWifi of the component Wifi Handler. Such manipulation of the argument wifiPwd leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attack can be launched remotely and requires low privileges. No user interaction is required.
Which deployment is known to be affected?
The affected product identified is Tenda AC5 running version 02.03.01.111_multi. The available information does not establish whether other versions or default configurations are affected.
Is public exploit information available?
Yes. The exploit has been publicly disclosed and may be used.
Which interface should be investigated for exposure?
Investigate access to the router's Wifi Handler endpoint at /goform/setWifi, particularly whether it is reachable by remote attackers. The vulnerable input is the wifiPwd argument.