CVE-2026-5156: Tenda CH22 Parameter QuickIndex formQuickIndex stack-based overflow
A vulnerability was determined in Tenda CH22 1.0.0.1. This impacts the function formQuickIndex of the file /goform/QuickIndex of the component Parameter Handler. This manipulation of the argument mitlinktype causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5156?
CVE-2026-5156 is classified as a high severity vulnerability due to its potential for stack-based overflow exploitation.
How do I fix CVE-2026-5156?
To mitigate CVE-2026-5156, update the Tenda CH22 firmware to the latest available version that addresses this vulnerability.
What type of vulnerability is CVE-2026-5156?
CVE-2026-5156 is a stack-based buffer overflow vulnerability affecting the formQuickIndex parameter in the Tenda CH22.
What component is affected by CVE-2026-5156?
CVE-2026-5156 affects the Parameter Handler component of the Tenda CH22 software.
Is CVE-2026-5156 remotely exploitable?
Yes, CVE-2026-5156 can be remotely exploited if an attacker manipulates specific parameters.