CVE-2026-5604: Tenda CH22 Parameter CertLocalPrecreate formCertLocalPrecreate stack-based overflow
A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formCertLocalPrecreate of the file /goform/CertLocalPrecreate of the component Parameter Handler. Performing a manipulation of the argument standard results in stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5604?
CVE-2026-5604 is rated as critical due to its potential for stack-based overflow leading to remote code execution.
How do I fix CVE-2026-5604?
To fix CVE-2026-5604, users should update to the latest firmware version that addresses the vulnerability.
What software is affected by CVE-2026-5604?
CVE-2026-5604 affects the Tenda CH22 with firmware version 1.0.0.1.
What type of vulnerability is CVE-2026-5604?
CVE-2026-5604 is classified as a stack-based buffer overflow vulnerability.
Can CVE-2026-5604 exploit my device remotely?
Yes, CVE-2026-5604 can be exploited remotely by sending crafted requests to the affected device.