CVE-2026-5156
HIGHA vulnerability was determined in Tenda CH22 1.0.0.1. This impacts the function formQuickIndex of the file /goform/QuickIndex of the component Parameter Handler. This manipulation of the argument mit_linktype causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
Published: 3/31/2026Modified: 4/2/2026
References (5)
https://github.com/Litengzheng/vuldb_new/blob/main/CH22/vul_46/README.mdExploitThird Party Advisoryhttps://vuldb.com/submit/780208Third Party AdvisoryVDB Entryhttps://vuldb.com/vuln/354188Third Party AdvisoryVDB Entryhttps://vuldb.com/vuln/354188/ctiPermissions RequiredVDB Entryhttps://www.tenda.com.cn/Product