CVE-2026-4903: Tenda AC5 POST Request QuickIndex formQuickIndex memory corruption
A flaw has been found in Tenda AC5 15.03.06.47. This vulnerability affects the function formQuickIndex of the file /goform/QuickIndex of the component POST Request Handler. This manipulation of the argument PPPOEPassword causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4903?
CVE-2026-4903 has been rated as a high severity memory corruption vulnerability.
How do I fix CVE-2026-4903?
To remediate CVE-2026-4903, update the Tenda AC5 to a version that addresses this vulnerability.
What components are affected by CVE-2026-4903?
CVE-2026-4903 affects the POST Request Handler component specifically in the formQuickIndex function.
What version of Tenda AC5 is impacted by CVE-2026-4903?
Only Tenda AC5 version 15.03.06.47 is impacted by CVE-2026-4903.
What type of attack can exploit CVE-2026-4903?
CVE-2026-4903 can be exploited through crafted POST requests that manipulate the PPPOEPassword argument.