CVE-2026-5152

Publication date

2026-03-30 20:30:17

Family

VulDB

State

PUBLISHED

Description

A vulnerability was detected in Tenda CH22 1.0.0.1. Impacted is the function formCreateFileName of the file /goform/createFileName. Performing a manipulation of the argument fileNameMit results in stack-based buffer overflow. The attack may be initiated remotely. The exploit is now public and may be used.