CVE-2026-5154
HIGHTenda CH22 Parameter setcfm fromSetCfm stack-based overflow
Title source: cnaDescription
A vulnerability has been found in Tenda CH22 1.0.0.1/1.If. The impacted element is the function fromSetCfm of the file /goform/setcfm of the component Parameter Handler. The manipulation of the argument funcname leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Scores
CVSS v3
8.8
EPSS
0.0005
EPSS Percentile
15.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-119
CWE-121
Status
published
Products (2)
Tenda/CH22
1.0.0.1
Tenda/CH22
1.If
Published
Mar 30, 2026
Tracked Since
Mar 31, 2026