← Back
CVE-2026-5604
high
CVSS 8.8
A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formCertLocalPrecreate of the file /goform/CertLocalPrecreate of the component Parameter Handler. Perfor...
Summary
A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formCertLocalPrecreate of the file /goform/CertLocalPrecreate of the component Parameter Handler. Performing a manipulation of the argument standard results in stack-based buffer overflow. Remote exploita...
AI summary openai / gpt-4o
Tenda CH22 1.0.0.1において、Parameter HandlerコンポーネントのformCertLocalPrecreate関数に脆弱性が発見されました。特定の引数を操作することで、スタックベースのバッファオーバーフローが引き起こされ、リモートからの攻撃が可能です。この脆弱性のエクスプロイトは公表されており、攻撃に用いられる可能性があります。
❓ What is the problem
Tenda CH22の特定の引数操作によりスタックベースのバッファオーバーフローが発生する脆弱性。
📍 Affected scope
Tenda CH22 1.0.0.1のParameter HandlerコンポーネントのformCertLocalPrecreate関数
🔥 Severity
リモートからの攻撃が可能で高い危険性がある。エクスプロイトが公になっているため悪用されるリスクがある。
🔧 How to fix
情報なし
🛡️ Workaround
情報なし
🔍 Detection
公開されたエクスプロイトを用いて影響を受けるかどうか確認する。
References
- advisory [email protected]
- advisory [email protected]
- exploit [email protected]
- web [email protected]
- web [email protected]