Stack-Based Buffer Overflow in Tenda CX12L Router
CVE-2026-5686
Key Information:
Badges
What is CVE-2026-5686?
A security vulnerability has been identified in the Tenda CX12L router's handling of the RouteStatic function, specifically affecting the /goform/RouteStatic file. An attacker can exploit this flaw by manipulating the 'page' argument, leading to a stack-based buffer overflow. The nature of this vulnerability allows remote exploitation, posing significant security risks. The details of the exploit have been made public, increasing the urgency for affected users to implement necessary mitigations.
Affected Version(s)
CX12L 16.03.53.12
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved