CVE-2026-4902
8.8Tenda · AC5
A stack-based buffer overflow in the Tenda AC5 web interface allows remote attackers to trigger memory corruption via a crafted POST request to the addressNat function.
Executive summary
A remote stack-based buffer overflow vulnerability in the Tenda AC5 router poses a high risk of system compromise due to the availability of public exploit details.
Vulnerability
The vulnerability exists in the fromAddressNat function within the /goform/addressNat component. An attacker with low-level privileges can trigger a stack-based buffer overflow by sending a manipulated page argument in a POST request, leading to potential memory corruption.
Business impact
Successful exploitation of this flaw allows an attacker to achieve remote code execution or cause a denial of service on the affected network device. Given the CVSS score of 8.8, this vulnerability represents a severe threat to internal network integrity, potentially allowing unauthorized actors to intercept traffic or gain persistent access to the network infrastructure.
Remediation
Immediate Action: Since a specific patch is currently unknown, administrators should restrict network access to the device management interface to trusted IP addresses only. Disable remote management features if they are not strictly required for business operations.
Proactive Monitoring: Monitor device logs for anomalous POST requests directed at the /goform/addressNat endpoint. Investigate any sudden crashes or unexpected reboots of the router, which may indicate exploitation attempts.
Compensating Controls: Deploy a Web Application Firewall or similar network security appliance to inspect incoming HTTP traffic for malformed payloads targeting the addressNat function.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists and is documented in the technical write-up provided by the researcher.
Analyst recommendation
The severity of this vulnerability, combined with the presence of a public proof-of-concept, necessitates immediate action to isolate the device. Security teams must prioritize limiting exposure by disabling remote administration and applying firmware updates as soon as the vendor releases a corrective patch.
More Tenda CVEs
Sources
Originally found and disclosed by wxhwxhwxh_mie (VulDB User), per the CVE Program record.
- VDB-353653 | Tenda AC5 POST Request addressNat fromAddressNat memory corruption Vulnerability database entry
- VDB-353653 | CTI Indicators (IOB, IOC, IOA)
- Submit #777378 | Tenda AC5 AC5 V1.0 V15.03.06.47 Buffer Overflow Third-party advisory
- Exploit / PoC
- tenda.com.cn