CVE-2026-5604Disclosure(tenda / ch22)

LOWCVSS 7.4 · HIGH

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Prioritize remediation for tenda ch22 systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formCertLocalPrecreate of the file /goform/CertLocalPrecreate of the component Parameter Handler. Performing a manipulation of the argument standard results in stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ch22
  • ch22_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • 7 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 5 mentions (2026-04-05); latest day: 2
  • 7 total mentions across 2 days

Affected systems

Vendors
Products
ch22ch22_firmware

2 versions affected across 2 products

Deep dive

Activity timeline7 mentions / 2d
01345Mentions · 2026-04-05: 5Mentions · 2026-04-06: 2Active Exploitation · 2026-04-05: 1Technical Details · 2026-04-05: 4Technical Details · 2026-04-06: 204-0504-06
Signal classification3 categories
Disclosure
571.4%
Active Exploitation
114.3%
General
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-055
Active Exploitation1Disclosure3General1
2026-04-062
Disclosure2
Full discourse7 posts
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-5604 - Tenda CH22 Parameter CertLocalPrecreate formCertLocalPrecreate stack-based overflow Intel Report: https://ift.tt/bWNmgvL

    Post summary

    The alert announces CVE-2026-5604, a stack‑based overflow in Tenda CH22’s CertLocalPrecreate parameter, providing technical details but no PoC or evidence of exploitation.

    0000036
    281 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-5604 - Tenda CH22 Parameter CertLocalPrecreate formCertLocalPrecreate stack-based overflow Intel Report: https://ift.tt/VsyXAla

    Post summary

    The tweet announces a stack-based overflow vulnerability (CVE-2026-5604) in the Tenda CH22 device, referencing an Intel report for further details.

    0000035
    281 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5604 A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formCertLocalPrecreate of the file /goform/CertLocalPrecreate of the com… https://www.cve.org/CVERecord?id=CVE-2026-5604 ----- Traducción: CVE-2026-5604 Se … http://infoflow.cloud`

    Post summary

    The post announces the discovery of CVE-2026-5604 in Tenda CH22 firmware, identifying the affected function formCertLocalPrecreate.

    0000041
    63 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-5604 A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formCertLocalPrecreate of the file /goform/CertLocalPrecreate of the com… https://www.cve.org/CVERecord?id=CVE-2026-5604

    Post summary

    The text announces the discovery of CVE-2026-5604 in the Tenda CH22 firmware, identifying the affected function and file, but provides no PoC, exploit, or patch information.

    00000641
    56.8K followersView on X
  • DFIR Lab@DFIR_Lab
    Active Exploitation

    ```json { "x": "🚨 CVE-2026-5604 | CVSS 8.8 HIGH\n\nStack-based buffer overflow in Tenda CH22 1[.]0[.]0[.]1 router. Publicly exploited.

    Post summary

    CVE-2026-5604, a stack-based buffer overflow in Tenda CH22 routers, is actively exploited in the wild, though no PoC or exploit code is provided.

    0000040
    1 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-5604: HIGH] Critical security flaw found in Tenda CH22 1.0.0.1! Vulnerability in formCertLocalPrecreate function may lead to remote stack-based buffer overflow attack. Exploit now public. #cybersecurity#cve,CVE-2026-5604,#cybersecurity https://cvefind.com/CVE-2026-5604

    Post summary

    CVE-2026-5604 reveals a remote stack‑based buffer overflow in Tenda CH22's formCertLocalPrecreate function; the exploit is reported as public, but no patch, detailed PoC, or active exploitation evidence is provided.

    0000049
    612 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    There is a new vulnerability with elevated criticality in Tenda CH22 (CVE-2026-5604) https://vuldb.com/vuln/355396

    Post summary

    A new critical vulnerability (CVE-2026-5604) in Tenda CH22 has been announced, but no technical, exploit, or patch details are provided.

    0000099
    2.1K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendach22---
OStendach22_firmware1.0.0.1--

Explore more