CVE-2026-5526Disclosure(tenda / 4g03_pro)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A security flaw has been discovered in Tenda 4G03 Pro up to 1.0/1.1/04.03.01.53/192.168.0.1. Affected by this vulnerability is an unknown functionality of the file /bin/httpd. The manipulation results in improper access controls. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-266CWE-284

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 4g03_pro
  • 4g03_pro_firmware

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-04); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
4g03_pro4g03_pro_firmware

2 versions affected across 2 products

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-04-04: 2Mentions · 2026-04-05: 2PoC Mentioned / Linked · 2026-04-05: 1Technical Details · 2026-04-05: 204-0404-05
Signal classification3 categories
Disclosure
250.0%
General
125.0%
PoC
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-042
Disclosure1General1
2026-04-052
Disclosure1PoC1
Full discourse4 posts
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    PoC

    🔓 CVE-2026-5526: Tenda 4G03 Pro improper access controls w/ public exploit. Tenda takeover! https://www.tenable.com/cve/CVE-2026-5526

    Post summary

    The tweet announces CVE-2026-5526 for Tenda 4G03 Pro with a public exploit, but offers limited technical detail, no patch, and no evidence of active exploitation.

    1002018
    1.4K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-5526 A security flaw has been discovered in Tenda 4G03 Pro up to 1.0/1.1/04.03.01.53/192.168.0.1. Affected by this vulnerability is an unknown functionality of the file /bin… https://www.cve.org/CVERecord?id=CVE-2026-5526

    Post summary

    The post announces CVE‑2026‑5526 for a Tenda device but provides only a cursory description and a link to the CVE record, with no detailed technical or exploitation information.

    10000626
    57.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-5526 - Tenda 4G03 Pro httpd access control Intel Report: https://ift.tt/SryUQk7

    Post summary

    The alert announces the newly disclosed CVE-2026-5526 affecting Tenda 4G03 Pro, noting an httpd access control flaw, but offers no further specifics on exploitation or mitigation.

    0000046
    281 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5526 A security flaw has been discovered in Tenda 4G03 Pro up to 1.0/1.1/04.03.01.53/192.168.0.1. Affected by this vulnerability is an unknown functionality of the file /bin… https://www.cve.org/CVERecord?id=CVE-2026-5526 ----- Traducción: CVE-2026-5526 Se … http://infoflow.cloud`

    Post summary

    The text announces the discovery of CVE-2026-5526 in Tenda 4G03 Pro devices, but provides minimal technical detail and no evidence of exploitation, a PoC, or mitigation measures.

    0000043
    67 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtenda4g03_pro1.0--
OStenda4g03_pro_firmware04.03.01.53--

Explore more