CVE-2026-5152General(tenda / ch22)

LOWCVSS 7.4 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was detected in Tenda CH22 1.0.0.1. Impacted is the function formCreateFileName of the file /goform/createFileName. Performing a manipulation of the argument fileNameMit results in stack-based buffer overflow. The attack may be initiated remotely. The exploit is now public and may be used.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ch22
  • ch22_firmware

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-30); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
ch22ch22_firmware

2 versions affected across 2 products

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-30: 2Mentions · 2026-03-31: 1PoC Mentioned / Linked · 2026-03-30: 1Technical Details · 2026-03-30: 1Technical Details · 2026-03-31: 103-3003-31
Signal classification3 categories
General
133.3%
PoC
133.3%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-302
General1PoC1
2026-03-311
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-5152 A vulnerability was detected in Tenda CH22 1.0.0.1. Impacted is the function formCreateFileName of the file /goform/createFileName. Performing a manipulation of the arg… https://www.cve.org/CVERecord?id=CVE-2026-5152

    Post summary

    The statement cites CVE‑2026‑5152, outlining a vulnerability in Tenda CH22’s `formCreateFileName` function but provides no PoC, exploit, or patch details.

    00000124
    56.9K followersView on X
  • CVEFind.com@CveFindCom
    PoC

    [CVE-2026-5152: HIGH] Critical vulnerability found in Tenda CH22 1.0.0.1 allowing remote attacks via stack-based buffer overflow in formCreateFileName function. Public exploit available.#cve,CVE-2026-5152,#cybersecurity https://cvefind.com/CVE-2026-5152

    Post summary

    A critical stack-based buffer overflow (CVE‑2026‑5152) was discovered in Tenda CH22 firmware 1.0.0.1, with a publicly available exploit referenced, but no patches or mitigation steps are noted.

    0000053
    608 followersView on X
  • VulDB 🛡@vuldb
    General

    The severity is increased for this new vulnerability affecting Tenda CH22 (CVE-2026-5152) https://vuldb.com/vuln/354184

    Post summary

    The statement notes an increased severity for CVE-2026-5152 affecting Tenda CH22 but offers no additional technical or mitigation information.

    0000059
    2.1K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendach22---
OStendach22_firmware1.0.0.1--

Explore more