CVE-2026-4906Disclosure(tenda / ac5)

LOWCVSS 7.4 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was determined in Tenda AC5 15.03.06.47. The affected element is the function decodePwd of the file /goform/WizardHandle of the component POST Request Handler. Executing a manipulation of the argument WANT/WANS can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ac5
  • ac5_firmware

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked at 4 mentions on most recent observed day (2026-03-27)
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
ac5ac5_firmware

2 versions affected across 2 products

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-03-26: 1Mentions · 2026-03-27: 4Technical Details · 2026-03-27: 403-2603-27
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-261
Disclosure1
2026-03-274
Disclosure3General1
Full discourse5 posts
  • VulDB 🛡@vuldb
    Disclosure

    A new vulnerability with increased severity was disclosed for Tenda AC5 (CVE-2026-4906) https://vuldb.com/?id.353657

    Post summary

    The post announces the disclosure of a new vulnerability, CVE‑2026‑4906, affecting the Tenda AC5 with higher severity, but provides no further technical details, PoC, or exploitation information.

    0101067
    2.1K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-4906: HIGH] Critical remote stack-based buffer overflow vulnerability found in Tenda AC5 15.03.06.47. Exploit publicly disclosed, execute caution. #cybersecurity#cve,CVE-2026-4906,#cybersecurity https://cvefind.com/CVE-2026-4906

    Post summary

    A high‑severity stack‑based buffer overflow (CVE‑2026‑4906) was disclosed for Tenda AC5 firmware 15.03.06.47; no exploit details or patch information were provided.

    0001061
    617 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4906 A vulnerability was determined in Tenda AC5 15.03.06.47. The affected element is the function decodePwd of the file /goform/WizardHandle of the component POST Request H… https://www.cve.org/CVERecord?id=CVE-2026-4906

    Post summary

    The information announces CVE-2026-4906 discovered in the Tenda AC5 firmware, detailing the affected file and function but does not discuss exploitation, patches, or a PoC.

    0000095
    56.9K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-4906 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4906 #CVE-2026-4906 #CVE #High #CyberSecurity #InfoSec https://t.co/VN92f9sOGT

    Post summary

    The tweet announces CVE-2026-4906, highlighting its high severity (8.8) and risk level, but offers no deeper technical insight, exploitation notes, or mitigation guidance.

    0000022
    123 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4906 - Tenda AC5 POST Request WizardHandle decodePwd stack-based overflow Intel Report: https://ift.tt/RgqBYOZ

    Post summary

    The post announces a stack‑based overflow vulnerability (CVE‑2026‑4906) in Tenda AC5 with a reference to an intel report, but it provides no PoC, exploit code, patch information, or evidence of active exploitation.

    0000032
    284 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendaac51.0--
OStendaac5_firmware15.03.06.47--

Explore more