PT-2026-29113 · Tenda · Tenda Ch22

Ltzhuster

·

Published

2026-03-30

·

Updated

2026-03-30

·

CVE-2026-5152

CVSS v2.0

9.0

High

AV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Tenda CH22 version 1.0.0.1
Description A buffer overflow exists in the formCreateFileName function located in the file /goform/createFileName. Manipulation of the fileNameMit argument can trigger a stack-based buffer overflow, potentially allowing for remote exploitation. The exploit for this issue is publicly available.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the /goform/createFileName endpoint to minimize the risk of exploitation. Avoid using the fileNameMit parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

Stack Overflow

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2026-5152

Affected Products

Tenda Ch22