CVE-2026-5830: Tenda AC15 SysToolChangePwd websGetVar stack-based overflow
A vulnerability was identified in Tenda AC15 15.03.05.18. This affects the function websGetVar of the file /goform/SysToolChangePwd. Such manipulation of the argument oldPwd/newPwd/cfmPwd leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5830?
CVE-2026-5830 is considered critical due to its potential for exploitation leading to a stack-based buffer overflow.
How do I fix CVE-2026-5830?
To fix CVE-2026-5830, update the Tenda AC15 firmware to the latest version that addresses the vulnerability.
What type of vulnerability is CVE-2026-5830?
CVE-2026-5830 is a stack-based buffer overflow vulnerability in the Tenda AC15 router.
What specific functions are affected by CVE-2026-5830?
CVE-2026-5830 affects the websGetVar function in the /goform/SysToolChangePwd file.
Which versions of Tenda AC15 are impacted by CVE-2026-5830?
CVE-2026-5830 specifically affects Tenda AC15 firmware version 15.03.05.18.