CVE-2026-5152: Tenda CH22 createFileName formCreateFileName stack-based overflow
A vulnerability was detected in Tenda CH22 1.0.0.1. Impacted is the function formCreateFileName of the file /goform/createFileName. Performing a manipulation of the argument fileNameMit results in stack-based buffer overflow. The attack may be initiated remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5152?
CVE-2026-5152 is classified as a high-severity vulnerability due to its potential for remote code execution via stack-based overflow.
How do I fix CVE-2026-5152?
To fix CVE-2026-5152, update the Tenda CH22 firmware to the latest version released by the manufacturer.
What is the impact of CVE-2026-5152?
The impact of CVE-2026-5152 is that attackers can exploit it to execute arbitrary code on the affected device.
Which devices are affected by CVE-2026-5152?
CVE-2026-5152 affects the Tenda CH22 model running version 1.0.0.1 firmware.
What is the nature of the vulnerability in CVE-2026-5152?
CVE-2026-5152 is a stack-based buffer overflow vulnerability that occurs in the formCreateFileName function.