CVE-2026-5154: Tenda CH22 Parameter setcfm fromSetCfm stack-based overflow
A vulnerability has been found in Tenda CH22 1.0.0.1/1.If. The impacted element is the function fromSetCfm of the file /goform/setcfm of the component Parameter Handler. The manipulation of the argument funcname leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5154?
CVE-2026-5154 is classified as a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2026-5154?
To mitigate CVE-2026-5154, update your Tenda CH22 to the latest firmware version available from the vendor.
What causes CVE-2026-5154?
CVE-2026-5154 is caused by a stack-based buffer overflow in the fromSetCfm function related to parameter handling.
What are the consequences of exploiting CVE-2026-5154?
Exploiting CVE-2026-5154 can allow an attacker to execute arbitrary code on the affected device.
Which Tenda CH22 versions are affected by CVE-2026-5154?
CVE-2026-5154 affects the Tenda CH22 firmware versions 1.0.0.1/1.If.