Junglewise Threat Intelligence

CVE-2026-5526: Tenda 4G03 Pro improper access control in httpd

CVE-2026-5526 · Severity: high · CVSS 7.3 · Published 2026-04-04

Vendors: Tenda.

Executive brief

A security vulnerability has been identified in the Tenda 4G03 Pro router, a device used to provide wireless internet connectivity. The flaw exists in the device's web management interface and could allow an unauthorized person to bypass security controls. If exploited, an attacker could gain unauthorized access to the device's settings or internal functions, potentially compromising the security of the local network.

Technical details

A vulnerability classified as improper access control (CWE-284/CWE-266) exists in the /bin/httpd binary of Tenda 4G03 Pro routers up to version 04.03.01.53. The flaw allows a remote, unauthenticated attacker to manipulate unknown functionality within the web server component to bypass intended access restrictions. This can lead to unauthorized configuration changes or access to sensitive device information. An exploit for this vulnerability has been released publicly, increasing the risk of active exploitation. Security engineers should monitor for unusual traffic to the router's management interface and apply firmware updates from the vendor if available.

Affected products

  • Tenda 4G03 Pro 1.0, 1.1, 04.03.01.53 and earlier

Timeline

  • 2026-04-04: disclosed: Initial public disclosure of the vulnerability
  • 2026-04-04: advisory: CVE-2026-5526 published

References

Related threats