CVE-2026-4904 is a high-severity stack-based buffer overflow vulnerability (CVSS 8.8) affecting Tenda AC5 15.03.06.47 and its firmware. This flaw resides in the `formSetCfm` function of the POST Request Handler, allowing a remote attacker to manipulate the `funcpara1` argument. With low privileges and no user interaction, successful exploitation can lead to a complete compromise of confidentiality, integrity, and availability. While not currently listed in the KEV catalog, the exploit has been publicly disclosed and may be used, though no specific exploit tools are noted in common databases. Community discussion and the EPSS score remain very low, indicating limited current attention and a low probability of widespread exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
15.03.06.47CPE matchmatch criteria | cpe:2.3:o:tenda:ac5_firmware:15.03.06.47:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.