CVE-2026-5830
8.8Tenda · AC15
A stack-based buffer overflow in Tenda AC15 version 15.03.05.18 allows remote attackers to trigger memory corruption via the websGetVar function in the SysToolChangePwd form.
Executive summary
A critical stack-based buffer overflow in the Tenda AC15 router allows remote attackers to achieve arbitrary code execution, posing a severe risk to network security.
Vulnerability
This vulnerability involves a stack-based buffer overflow located in the websGetVar function within the /goform/SysToolChangePwd endpoint. While the CVSS vector indicates that low privileges are required, the flaw allows an attacker to corrupt memory remotely by manipulating the oldPwd, newPwd, or cfmPwd arguments.
Business impact
The ability to trigger a buffer overflow in a network device often leads to remote code execution, granting an attacker full control over the router. This compromise can facilitate man-in-the-middle attacks, eavesdropping on internal traffic, and persistent unauthorized access to the local area network. Given the high CVSS score of 8.8, this flaw represents a significant threat to organizational data confidentiality and infrastructure integrity.
Remediation
Immediate Action: Administrators must contact the vendor to obtain and install the latest firmware update that addresses this specific buffer overflow vulnerability.
Proactive Monitoring: Security teams should monitor network traffic for anomalous HTTP POST requests directed at the /goform/SysToolChangePwd endpoint, which may indicate exploitation attempts.
Compensating Controls: Deploy a Web Application Firewall or similar inspection tool to filter or block malformed input parameters sent to the router management interface.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists in the form of a script provided via the vulnerability reference.
Analyst recommendation
The critical nature of this buffer overflow, combined with the availability of a public proof-of-concept, necessitates immediate action. Organizations utilizing the Tenda AC15 router must verify their firmware version and prioritize the application of any available security patches to prevent potential remote compromise of their network perimeter.
More Tenda CVEs
Sources
Originally found and disclosed by meshaal (VulDB User), per the CVE Program record.
- VDB-356277 | Tenda AC15 SysToolChangePwd websGetVar stack-based overflow Vulnerability database entry
- VDB-356277 | CTI Indicators (IOB, IOC, IOA)
- Submit #789178 | Tenda AC15 15.03.05.18 Memory Corruption Third-party advisory
- Exploit / PoC
- tenda.com.cn