CVE-2026-4904

8.8

Tenda · AC5

A stack-based buffer overflow in the Tenda AC5 POST request handler allows remote attackers to compromise system integrity via the funcpara1 argument.

Executive summary

A critical buffer overflow vulnerability in Tenda AC5 routers enables remote code execution and full system compromise.

Vulnerability

This vulnerability occurs within the formSetCfm function of the /goform/setcfm endpoint. It is a stack-based buffer overflow triggered by improper handling of the funcpara1 argument, which can be exploited by an authenticated attacker to achieve remote code execution.

Business impact

The CVSS score of 8.8 reflects a high severity risk that could lead to total system compromise, including loss of confidentiality, integrity, and availability. Successful exploitation allows an attacker to gain control over network infrastructure, potentially facilitating lateral movement within the corporate network or intercepting sensitive traffic.

Remediation

Immediate Action: Since a specific patch is not currently available, administrators should restrict access to the management interface to trusted IP addresses only and disable remote management features.

Proactive Monitoring: Monitor network traffic for unusual POST requests directed at the /goform/setcfm endpoint and audit system logs for unexpected crashes or reboot events.

Compensating Controls: Deploy a Web Application Firewall (WAF) or an Intrusion Prevention System (IPS) with rules configured to inspect and block malicious payloads targeting the funcpara1 parameter in Tenda administrative interfaces.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the referenced security researcher write-up.

Analyst recommendation

Given the high CVSS score and the existence of a public proof-of-concept, this vulnerability poses a significant risk to affected Tenda AC5 devices. Administrators must immediately isolate the management interface from external networks and remain vigilant for official vendor firmware updates to remediate the underlying memory corruption flaw.

More Tenda CVEs

Sources

Originally found and disclosed by wxhwxhwxh_mie (VulDB User), per the CVE Program record.