CVE-2026-4905Disclosure(tenda / ac5)

LOWCVSS 7.4 · HIGH

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was found in Tenda AC5 15.03.06.47. Impacted is the function formWifiWpsOOB of the file /goform/WifiWpsOOB of the component POST Request Handler. Performing a manipulation of the argument index results in stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made public and could be used.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ac5
  • ac5_firmware

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Exploit: 1 classified signal
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
ac5ac5_firmware

2 versions affected across 2 products

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-27: 3PoC Mentioned / Linked · 2026-03-27: 1Technical Details · 2026-03-27: 203-27
Signal classification3 categories
Disclosure
133.3%
Exploit
133.3%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-4905 A vulnerability was found in Tenda AC5 15.03.06.47. Impacted is the function formWifiWpsOOB of the file /goform/WifiWpsOOB of the component POST Request Handler. Perfor… https://www.cve.org/CVERecord?id=CVE-2026-4905

    Post summary

    CVE‑2026‑4905 was disclosed as affecting the Tenda AC5 router’s formWifiWpsOOB function; the post provides technical details but no PoC, exploit, or patch information.

    00000115
    56.9K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-4905 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4905 #CVE-2026-4905 #CVE #High #CyberSecurity #InfoSec https://t.co/FOWuhpeOTw

    Post summary

    The tweet merely announces the existence of CVE-2026-4905 with its severity and links to the NVD page, providing no technical or actionable information.

    0000033
    123 followersView on X
  • CVEFind.com@CveFindCom
    Exploit

    [CVE-2026-4905: HIGH] Vulnerability discovered in Tenda AC5 15.03.06.47 allows remote stack-based buffer overflow through manipulation of the argument index in formWifiWpsOOB function. Exploit now public.#cve,CVE-2026-4905,#cybersecurity https://cvefind.com/CVE-2026-4905

    Post summary

    CVE-2026-4905 is a stack‑based buffer overflow in Tenda AC5 devices; an exploit is now publicly available.

    0000047
    617 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendaac51.0--
OStendaac5_firmware15.03.06.47--

Explore more