CVE-2026-5686 is a stack-based buffer overflow vulnerability in Tenda CX12L router version 16.03.53.12, specifically within the fromRouteStatic function of the /goform/RouteStatic endpoint. The flaw can be triggered through manipulation of the page parameter and affects this router model exclusively. Public exploit code has been released for this vulnerability, increasing the risk of opportunistic attacks. The vulnerability carries a CVSS score of 8.8 (HIGH) with a network-based attack vector requiring low complexity and low privileges. Authentication is required to exploit this flaw, though no user interaction is necessary. Successful exploitation could allow an authenticated attacker to achieve complete compromise, including confidentiality, integrity, and availability violations on affected devices. While public exploit code exists, the vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities catalog, suggesting limited active exploitation in the wild at this time. The EPSS score of 0.00018 indicates relatively low statistical probability of exploitation compared to other CVEs, and community attention appears minimal with the vulnerability currently on inactive status. However, organizations managing Tenda CX12L routers should prioritize patching due to the public availability of exploit code and the severity of potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
16.03.53.12CPE matchmatch criteria | cpe:2.3:o:tenda:cx12l_firmware:16.03.53.12:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.