CVE-2026-5046: Tenda FH1201 Parameter WrlExtraSet formWrlExtraSet stack-based overflow
A flaw has been found in Tenda FH1201 1.2.0.14(408). Affected is the function formWrlExtraSet of the file /goform/WrlExtraSet of the component Parameter Handler. Executing a manipulation of the argument GO can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5046?
CVE-2026-5046 is classified as a critical stack-based overflow vulnerability affecting Tenda FH1201.
How do I fix CVE-2026-5046?
To mitigate CVE-2026-5046, update the Tenda FH1201 firmware to the latest version that addresses this vulnerability.
What products are affected by CVE-2026-5046?
CVE-2026-5046 affects the Tenda FH1201 with firmware version 1.2.0.14(408).
What is the impact of CVE-2026-5046?
CVE-2026-5046 can lead to remote code execution due to a stack-based buffer overflow during parameter handling.
How can I determine if my Tenda FH1201 is vulnerable to CVE-2026-5046?
Check the firmware version of your Tenda FH1201; if it matches 1.2.0.14(408), it is vulnerable to CVE-2026-5046.