BRIEFING NOTE - CVE-2026-5604 A stack-based buffer overflow vulnerability has been identified in Tenda CH22 version 1.0.0.1 within the formCertLocalPrecreate function of the /goform/CertLocalPrecreate endpoint. The flaw is triggered through manipulation of the standard parameter in the Parameter Handler component, allowing attackers to overwrite stack memory and potentially execute arbitrary code. The vulnerability carries a CVSS score of 8.8 (HIGH) with a network-based attack vector requiring only low complexity and low privileges to exploit. Remote attackers with minimal authentication can trigger the vulnerability without user interaction, resulting in high impact to confidentiality, integrity, and availability of affected systems. The FAUCET Risk Score of 51.0/100 reflects moderate concern within the threat landscape. Exploit code has been publicly released and is available for potential attackers to leverage. However, the vulnerability is not currently tracked in the CISA Known Exploited Vulnerabilities catalog and shows inactive status on threat intelligence hotlists. The low EPSS score of 0.0005 suggests current exploitation activity is limited, though the public availability of proof-of-concept code creates ongoing risk for organizations operating Tenda CH22 devices.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.0.1CPE matchmatch criteria | cpe:2.3:o:tenda:ch22_firmware:1.0.0.1:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.