CVE-2026-5156
8.8Tenda · CH22
A stack-based buffer overflow in the Tenda CH22 formQuickIndex function allows remote attackers to trigger memory corruption and potential code execution via the mit_linktype parameter.
Executive summary
A critical stack-based buffer overflow vulnerability in Tenda CH22 routers poses a severe risk of remote code execution for authenticated users.
Vulnerability
The vulnerability exists within the formQuickIndex function of the /goform/QuickIndex endpoint. By sending a crafted POST request with an oversized mit_linktype argument, an authenticated attacker can trigger a stack-based buffer overflow, leading to memory corruption or arbitrary code execution.
Business impact
The CVSS score of 8.8 reflects the high potential for system compromise. Successful exploitation could allow an attacker to gain full control over the networking device, facilitating unauthorized access to the internal network, traffic interception, or complete denial of service. Such a compromise poses a significant risk to the confidentiality, integrity, and availability of business operations.
Remediation
Immediate Action: Contact Tenda support or check the official Tenda website for firmware updates addressing this buffer overflow. If no patch is currently available, restrict access to the device management interface to trusted administrative IP addresses only.
Proactive Monitoring: Monitor device logs for unusual POST requests directed at the /goform/QuickIndex endpoint, particularly those containing excessively long parameter strings.
Compensating Controls: Deploy a Web Application Firewall or an intrusion prevention system to filter and block malformed HTTP requests that exceed expected length constraints for the mit_linktype parameter.
Exploitation status
Public Exploit Available: Yes, a proof-of-concept is documented in the researcher write-up linked in the vulnerability references.
Analyst recommendation
Given the availability of a public proof-of-concept and the high severity of potential remote code execution, this vulnerability represents a significant threat. Administrators must prioritize restricting management access to the affected Tenda CH22 devices immediately and apply vendor-supplied firmware updates as soon as they become available to mitigate the risk of unauthorized access.
More Tenda CVEs
Sources
Originally found and disclosed by LtzHust2 (VulDB User), per the CVE Program record.
- VDB-354188 | Tenda CH22 Parameter QuickIndex formQuickIndex stack-based overflow Vulnerability database entry
- VDB-354188 | CTI Indicators (IOB, IOC, IOA)
- Submit #780208 | Tenda CH22 V1.0.0.1 Stack-based Buffer Overflow Third-party advisory
- Exploit / PoC
- tenda.com.cn