CVE-2026-4902: Tenda AC5 POST Request addressNat fromAddressNat memory corruption
A vulnerability was detected in Tenda AC5 15.03.06.47. This affects the function fromAddressNat of the file /goform/addressNat of the component POST Request Handler. The manipulation of the argument page results in stack-based buffer overflow. The attack can be launched remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4902?
CVE-2026-4902 is considered a high severity vulnerability due to its potential for causing memory corruption and stack-based buffer overflow.
How do I fix CVE-2026-4902?
To fix CVE-2026-4902, users should update their Tenda AC5 firmware to the latest version provided by Tenda.
What is affected by CVE-2026-4902?
CVE-2026-4902 affects the Tenda AC5 router running firmware version 15.03.06.47.
What functionality is impacted by CVE-2026-4902?
The vulnerability impacts the POST Request Handler function fromAddressNat located in the /goform/addressNat file.
What could an attacker achieve by exploiting CVE-2026-4902?
An attacker exploiting CVE-2026-4902 could potentially execute arbitrary code or cause denial of service through memory corruption.