CVE-2026-4905
8.8Tenda · AC5
A stack-based buffer overflow in the Tenda AC5 router allows remote attackers to execute arbitrary code via a crafted index argument in the WifiWpsOOB function.
Executive summary
A critical stack-based buffer overflow vulnerability in Tenda AC5 routers, identified as CVE-2026-4905, exposes devices to potential remote code execution and full system compromise.
Vulnerability
The flaw exists within the formWifiWpsOOB function located in the /goform/WifiWpsOOB endpoint. By manipulating the index argument, an authenticated attacker can trigger a stack-based buffer overflow, leading to memory corruption and potential remote code execution.
Business impact
The vulnerability carries a high CVSS score of 8.8, reflecting the severity of a memory corruption flaw that can result in total loss of system integrity and availability. Successful exploitation allows an attacker to gain unauthorized control over network infrastructure, potentially facilitating lateral movement, data interception, or the creation of a persistent backdoor within the corporate network environment.
Remediation
Immediate Action: Since no official patch is currently identified, isolate affected Tenda AC5 devices from the public internet and restrict management access to trusted internal subnets only.
Proactive Monitoring: Monitor network traffic for unusual POST requests directed at the /goform/WifiWpsOOB endpoint and review system logs for signs of service crashes or unauthorized configuration changes.
Compensating Controls: Deploy Web Application Firewall (WAF) rules or network-level IPS signatures to detect and drop malicious payloads targeting the WPS configuration parameters.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists as detailed in the technical write-up provided by the researcher.
Analyst recommendation
Given the availability of a functional proof-of-concept and the potential for full system compromise, administrators must treat this vulnerability with high urgency. Until a vendor-supplied firmware update is released, strict network segmentation remains the most effective method to prevent unauthorized access to the vulnerable interface.
More Tenda CVEs
Sources
Originally found and disclosed by wxhwxhwxh_mie (VulDB User), per the CVE Program record.
- VDB-353656 | Tenda AC5 POST Request WifiWpsOOB formWifiWpsOOB stack-based overflow Vulnerability database entry
- VDB-353656 | CTI Indicators (IOB, IOC, IOA)
- Submit #777393 | Tenda AC5 AC5 V1.0 V15.03.06.47 Buffer Overflow Third-party advisory
- Exploit / PoC
- tenda.com.cn