PT-2026-29113 · Tenda · Tenda Ch22

·

CVE-2026-5152

·

Publicado

2026-03-30

·

Atualizado

2026-03-31

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Tenda CH22 version 1.0.0.1
Description A buffer overflow exists in the formCreateFileName function located in the file /goform/createFileName. Manipulation of the fileNameMit argument can trigger a stack-based buffer overflow, potentially allowing for remote exploitation. The exploit for this issue is publicly available.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the /goform/createFileName endpoint to minimize the risk of exploitation. Avoid using the fileNameMit parameter in the affected API endpoint until the issue is resolved.

Exploit

Correção

Memory Corruption

Buffer Overflow

Stack Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-5152

Produtos afetados

Tenda Ch22