CVE-2026-5204
HIGHA vulnerability was determined in Tenda CH22 1.0.0.1. Affected is the function formWebTypeLibrary of the file /goform/webtypelibrary of the component Parameter Handler. This manipulation of the argument webSiteId causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Published: 3/31/2026Modified: 4/2/2026
References (5)
https://github.com/Litengzheng/vuldb_new/blob/main/CH22/vul_49/README.mdExploitThird Party Advisoryhttps://vuldb.com/submit/780209Third Party AdvisoryVDB Entryhttps://vuldb.com/vuln/354332Third Party AdvisoryVDB Entryhttps://vuldb.com/vuln/354332/ctiPermissions RequiredVDB Entryhttps://www.tenda.com.cn/Product