CVE-2026-4960: Tenda AC6 POST Request WizardHandle fromWizardHandle stack-based overflow
A vulnerability was determined in Tenda AC6 15.03.05.16. Affected is the function fromWizardHandle of the file /goform/WizardHandle of the component POST Request Handler. Executing a manipulation of the argument WANT/WANS can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4960?
CVE-2026-4960 is a high severity vulnerability affecting the Tenda AC6 router.
How do I fix CVE-2026-4960?
To mitigate CVE-2026-4960, upgrade the Tenda AC6 to the latest firmware version available from the manufacturer.
What type of vulnerability is CVE-2026-4960?
CVE-2026-4960 is a stack-based buffer overflow vulnerability in the POST Request Handler component.
Which systems are affected by CVE-2026-4960?
CVE-2026-4960 specifically affects the Tenda AC6 with firmware version 15.03.05.16.
What potential impact does CVE-2026-4960 have?
Exploiting CVE-2026-4960 could allow an attacker to execute arbitrary code on the affected Tenda AC6 device.