CVE-2026-5204: Tenda CH22 Parameter webtypelibrary formWebTypeLibrary stack-based overflow
A vulnerability was determined in Tenda CH22 1.0.0.1. Affected is the function formWebTypeLibrary of the file /goform/webtypelibrary of the component Parameter Handler. This manipulation of the argument webSiteId causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5204?
CVE-2026-5204 has been classified as a high severity vulnerability due to the potential for stack-based overflow leading to arbitrary code execution.
How do I fix CVE-2026-5204?
To fix CVE-2026-5204, users should update Tenda CH22 to the latest patch provided by the vendor that addresses this stack-based overflow issue.
What does CVE-2026-5204 affect?
CVE-2026-5204 specifically affects the Tenda CH22 version 1.0.0.1 in the function formWebTypeLibrary within the Parameter Handler.
What are the potential impacts of CVE-2026-5204?
Successful exploitation of CVE-2026-5204 can lead to remote code execution, allowing attackers to gain unauthorized access to the affected device.
Is CVE-2026-5204 easy to exploit?
Exploitation of CVE-2026-5204 is considered relatively straightforward for attackers with knowledge of stack overflow techniques.