CVE-2026-5154

HIGH

Tenda CH22 Parameter setcfm fromSetCfm stack-based overflow

Title source: cna

Description

A vulnerability has been found in Tenda CH22 1.0.0.1/1.If. The impacted element is the function fromSetCfm of the file /goform/setcfm of the component Parameter Handler. The manipulation of the argument funcname leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.

Scores

CVSS v3 8.8
EPSS 0.0005
EPSS Percentile 15.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119 CWE-121
Status published
Products (2)
Tenda/CH22 1.0.0.1
Tenda/CH22 1.If
Published Mar 30, 2026
Tracked Since Mar 31, 2026