CVE-2026-4975: Tenda AC15 POST Request setcfm formSetCfm memory corruption
A vulnerability has been found in Tenda AC15 15.03.05.19. This affects the function formSetCfm of the file /goform/setcfm of the component POST Request Handler. The manipulation of the argument funcpara1 leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4975?
CVE-2026-4975 has a high severity due to its potential for stack-based buffer overflow exploits.
How do I fix CVE-2026-4975?
To fix CVE-2026-4975, update the Tenda AC15 firmware to a version that addresses this vulnerability.
What is the affected version of Tenda AC15 for CVE-2026-4975?
CVE-2026-4975 affects Tenda AC15 version 15.03.05.19.
What component is impacted by CVE-2026-4975?
CVE-2026-4975 impacts the POST Request Handler in the function formSetCfm.
What type of vulnerability is CVE-2026-4975?
CVE-2026-4975 is classified as a memory corruption vulnerability due to a stack-based buffer overflow.