CVE-2026-4904Disclosure(tenda / ac5)

LOWCVSS 7.4 · HIGH

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Prioritize remediation for tenda ac5 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A vulnerability has been found in Tenda AC5 15.03.06.47. This issue affects the function formSetCfm of the file /goform/setcfm of the component POST Request Handler. Such manipulation of the argument funcpara1 leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ac5
  • ac5_firmware

Threat summary

  • Public PoC and exploit tooling are both present
  • 3 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
ac5ac5_firmware

2 versions affected across 2 products

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-27: 3PoC Mentioned / Linked · 2026-03-27: 1Exploit Tool / Code · 2026-03-27: 1Technical Details · 2026-03-27: 103-27
Signal classification2 categories
Disclosure
266.7%
Exploit
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-4904 A vulnerability has been found in Tenda AC5 15.03.06.47. This issue affects the function formSetCfm of the file /goform/setcfm of the component POST Request Handler. Su… https://www.cve.org/CVERecord?id=CVE-2026-4904

    Post summary

    The text announces a newly identified vulnerability, CVE-2026-4904, in the Tenda AC5 firmware that impacts the POST request handler function "formSetCfm" within the /goform/setcfm file.

    00000111
    56.9K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-4904 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4904 #CVE-2026-4904 #CVE #High #CyberSecurity #InfoSec https://t.co/ulD3L8Bqwk

    Post summary

    The tweet simply announces the existence of CVE-2026-4904 with an 8.8 severity rating, but omits technical details, exploitation evidence, or patch information.

    0000030
    123 followersView on X
  • CVEFind.com@CveFindCom
    Exploit

    [CVE-2026-4904: HIGH] Critical vulnerability found in Tenda AC5 15.03.06.47! Stack-based buffer overflow via manipulation of funcpara1 in /goform/setcfm opens remote attack vector. Public exploit available.#cve,CVE-2026-4904,#cybersecurity https://cvefind.com/CVE-2026-4904

    Post summary

    A critical stack‑based buffer overflow reported in Tenda AC5 firmware, with a publicly available exploit, but no patch or active exploitation evidence.

    0000054
    617 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendaac51.0--
OStendaac5_firmware15.03.06.47--

Explore more