CVE-2026-4904: Tenda AC5 POST Request setcfm formSetCfm stack-based overflow
A vulnerability has been found in Tenda AC5 15.03.06.47. This issue affects the function formSetCfm of the file /goform/setcfm of the component POST Request Handler. Such manipulation of the argument funcpara1 leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4904?
CVE-2026-4904 has a high severity rating due to the possibility of stack-based buffer overflow.
How do I fix CVE-2026-4904?
Fix CVE-2026-4904 by updating the Tenda AC5 firmware to the latest version released by the manufacturer.
What are the potential impacts of exploiting CVE-2026-4904?
Exploitation of CVE-2026-4904 can lead to remote code execution, system crashes, or unauthorized access to the device.
Which versions are affected by CVE-2026-4904?
CVE-2026-4904 affects Tenda AC5 with firmware version 15.03.06.47.
Is there a workaround for CVE-2026-4904 if I cannot update?
A temporary workaround for CVE-2026-4904 is to limit access to the Tenda AC5 device and restrict unauthorized network traffic.