Junglewise Threat Intelligence

CVE-2026-5204: Tenda CH22 stack buffer overflow in formWebTypeLibrary

CVE-2026-5204 · Severity: high · CVSS 8.8 · Published 2026-03-31

Technologies: Tenda Ch22 Firmware, Tenda CH22. Vendors: Tenda.

Executive brief

A security vulnerability has been identified in the Tenda CH22, a networking device. An attacker could exploit this flaw to cause the device to crash or potentially take full control of it by sending a specially crafted web request. This could lead to a total loss of network availability or unauthorized access to data passing through the device.

Technical details

A stack-based buffer overflow vulnerability exists in the Tenda CH22 firmware version 1.0.0.1. The flaw is located within the 'formWebTypeLibrary' function in the '/goform/webtypelibrary' component of the Parameter Handler. The root cause is an unsafe 'strcat' operation on the user-provided 'webSiteId' parameter without adequate length validation. A remote attacker with low privileges can trigger this overflow by sending a crafted POST request, potentially leading to remote code execution (RCE) or a denial of service (DoS) condition. A proof-of-concept exploit has been publicly disclosed.

Affected products

  • Tenda CH22 1.0.0.1

Timeline

  • 2026-03-31: disclosed: Vulnerability disclosed and CVE assigned
  • 2026-03-31: advisory: Initial advisory published by VulDB

References

Related threats