CVE-2026-4905 | Tenda AC5 15.03.06.47 POST Request /goform/WifiWpsOOB formWifiWpsOOB index stack-based overflow (EUVD-2026-16476)
A vulnerability, which was classified as critical, has been found in Tenda AC5 15.03.06.47. Impacted is the function formWifiWpsOOB of the file /goform/WifiWpsOOB of the component POST Request Handler. Performing a manipulation of the argument index results in stack-based buffer overflow.
This vulnerability is known as CVE-2026-4905. Remote exploitation of the attack is possible. Furthermore, an exploit is available.