CVE-2026-5036Disclosure(tenda / 4g06)

LOWCVSS 7.4 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was found in Tenda 4G06 04.06.01.29. This vulnerability affects the function fromDhcpListClient of the file /goform/DhcpListClient of the component Endpoint. Performing a manipulation of the argument page results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made public and could be used.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-119CWE-121

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 4g06
  • 4g06_firmware

Threat summary

  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-03-29)
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
4g064g06_firmware

2 versions affected across 2 products

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-03-27: 1Mentions · 2026-03-28: 1Mentions · 2026-03-29: 3Technical Details · 2026-03-29: 103-2703-2803-29
Signal classification2 categories
Disclosure
360.0%
General
240.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-271
Disclosure1
2026-03-281
General1
2026-03-293
Disclosure2General1
Full discourse5 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-5036 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-5036 #CVE-2026-5036 #CVE #High #CyberSecurity #InfoSec https://t.co/uQ4KfICKXt

    Post summary

    The tweet announces the newly identified CVE-2026-5036 with a high severity rating of 8.8, directing readers to the NVD for details, but provides no further technical or exploit information.

    0001031
    123 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-5036 A vulnerability was found in Tenda 4G06 04.06.01.29. This vulnerability affects the function fromDhcpListClient of the file /goform/DhcpListClient of the component Endp… https://www.cve.org/CVERecord?id=CVE-2026-5036

    Post summary

    The CVE-2026-5036 entry reports a vulnerability in a Tenda device's DHCP function, but provides no details on exploitation, mitigation, or supporting PoC.

    0000091
    56.9K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-5036: HIGH] Vulnerability in Tenda 4G06 04.06.01.29 can lead to a remote stack-based buffer overflow through manipulation of arguments in the fromDhcpListClient function. Exploit is public.#cve,CVE-2026-5036,#cybersecurity https://cvefind.com/CVE-2026-5036

    Post summary

    A new high‑severity vulnerability (CVE‑2026‑5036) in Tenda 4G06 routers can cause a remote stack‑based buffer overflow via manipulation of the fromDhcpListClient function arguments; no exploit code, active exploitation, or patch is discussed.

    0000033
    617 followersView on X
  • VulDB 🛡@vuldb
    General

    A new vulnerability with increased severity was disclosed for Tenda 4G06 (CVE-2026-5036) https://vuldb.com/vuln/353962

    Post summary

    A brief disclosure of CVE-2026-5036 for a Tenda 4G06 device with no supporting technical or patch details.

    0000056
    2.1K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A new vulnerability with increased severity was disclosed for Tenda 4G06 (CVE-2026-5036) https://vuldb.com/?id.353962

    Post summary

    A disclosure of CVE-2026-5036 affecting the Tenda 4G06 device is announced, with no additional technical details or mitigation information provided.

    0000056
    2.1K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtenda4g063.0--
OStenda4g06_firmware04.06.01.29--

Explore more