HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-5204 — A vulnerability was determined in Tenda CH22 1.0.0.1. Affected is the function f...

Tuesday, March 31, 2026 at 04:16 PM UTC·Source: NIST NVD

Updated: Monday, April 6, 2026 at 08:17 AM UTC

Executive Summary

A vulnerability was determined in Tenda CH22 1.0.0.1. Affected is the function formWebTypeLibrary of the file /goform/webtypelibrary of the component Parameter Handler. This manipulation of the argument webSiteId causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.

Analysis

A vulnerability was determined in Tenda CH22 1.0.0.1. Affected is the function formWebTypeLibrary of the file /goform/webtypelibrary of the component Parameter Handler. This manipulation of the argument webSiteId causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. CVSS Score: 8.8. Published: 2026-03-31T16:16:35.973.

Indicators of Compromise (2)

CVE (1)
CVE-2026-5204
Source Attribution

Originally published by NIST NVD on Mar 31, 2026. Verified by: NIST.

Related Threats