HIGHVulnerability
Verified
Global
NVD HIGH: CVE-2026-5204 — A vulnerability was determined in Tenda CH22 1.0.0.1. Affected is the function f...
Tuesday, March 31, 2026 at 04:16 PM UTC·Source: NIST NVD
Updated: Monday, April 6, 2026 at 08:17 AM UTC
Executive Summary
A vulnerability was determined in Tenda CH22 1.0.0.1. Affected is the function formWebTypeLibrary of the file /goform/webtypelibrary of the component Parameter Handler. This manipulation of the argument webSiteId causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Analysis
A vulnerability was determined in Tenda CH22 1.0.0.1. Affected is the function formWebTypeLibrary of the file /goform/webtypelibrary of the component Parameter Handler. This manipulation of the argument webSiteId causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. CVSS Score: 8.8. Published: 2026-03-31T16:16:35.973.