CVE-2026-4905: Tenda AC5 POST Request WifiWpsOOB formWifiWpsOOB stack-based overflow
A vulnerability was found in Tenda AC5 15.03.06.47. Impacted is the function formWifiWpsOOB of the file /goform/WifiWpsOOB of the component POST Request Handler. Performing a manipulation of the argument index results in stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4905?
CVE-2026-4905 is classified as a critical vulnerability due to its potential to cause stack-based overflow, leading to arbitrary code execution.
How do I fix CVE-2026-4905?
To fix CVE-2026-4905, update the Tenda AC5 firmware to the latest version provided by the vendor.
What versions are affected by CVE-2026-4905?
CVE-2026-4905 affects the Tenda AC5 with firmware version 15.03.06.47.
What is the impact of CVE-2026-4905?
The impact of CVE-2026-4905 includes the risk of unauthorized access and potential remote code execution on the affected device.
What component is vulnerable in CVE-2026-4905?
The vulnerable component in CVE-2026-4905 is the POST Request Handler, specifically the formWifiWpsOOB function in the /goform/WifiWpsOOB file.