CVE-2026-4903
8.8Tenda · AC5
A stack-based buffer overflow in the Tenda AC5 router allows remote attackers to trigger memory corruption via the PPPOEPassword parameter in the formQuickIndex function.
Executive summary
A remote, unauthenticated-accessible stack-based buffer overflow in Tenda AC5 routers presents a critical risk of system compromise and potential code execution.
Vulnerability
The vulnerability exists in the formQuickIndex function within the /goform/QuickIndex endpoint. By manipulating the PPPOEPassword argument, an attacker can trigger a stack-based buffer overflow, leading to memory corruption.
Business impact
The vulnerability carries a CVSS score of 8.8, reflecting its high potential for full system compromise. Successful exploitation could lead to unauthorized control of network routing equipment, resulting in traffic interception, denial of service, or lateral movement into the local network environment.
Remediation
Immediate Action: Since no official patch is currently identified for this specific firmware version, administrators should isolate affected devices from the public internet immediately and restrict management access to trusted internal IP addresses.
Proactive Monitoring: Review system logs for unusual POST requests directed at /goform/QuickIndex and monitor for unexpected service restarts or abnormal memory usage on the device.
Compensating Controls: Deploy a Web Application Firewall (WAF) or an Intrusion Prevention System (IPS) with custom signatures to inspect and block malformed PPPOEPassword parameters in HTTP requests.
Exploitation status
Public Exploit Available: Yes — a published proof-of-concept exists in the researcher write-up linked by the CVE record.
Analyst recommendation
Given the availability of a public proof-of-concept and the potential for remote code execution, this vulnerability poses a significant threat to organizational security. We strongly advise users to minimize the exposure of the administrative interface to external networks and to coordinate with Tenda for firmware updates that address this stack-based buffer overflow.
More Tenda CVEs
Sources
Originally found and disclosed by wxhwxhwxh_mie (VulDB User), per the CVE Program record.
- VDB-353654 | Tenda AC5 POST Request QuickIndex formQuickIndex memory corruption Vulnerability database entry
- VDB-353654 | CTI Indicators (IOB, IOC, IOA)
- Submit #777380 | Tenda AC5 AC5 V1.0 V15.03.06.47 Buffer Overflow Third-party advisory
- Exploit / PoC
- tenda.com.cn