CVE-2026-105778 is a remotely exploitable stack-based buffer overflow in Tenda AC5 firmware 02.03.01.111_multi, reachable through the wifiPwd argument of /goform/setWifi, and a public exploit has been disclosed.
What Is It
CVE-2026-105778 is a stack-based buffer overflow (CWE-121, CWE-119) in the Wifi Handler component of Tenda AC5 firmware. According to the VulDB CNA description, manipulating the wifiPwd argument sent to the /goform/setWifi endpoint triggers the overflow. The record says the affected functionality is "unknown" beyond that file and parameter.
NVD published the record on 2026-10-06, and its status is still "Received," so NVD has not yet analyzed it independently. All scoring comes from the CNA (VulDB).
Why It Matters
- CVSS 3.1: 9.9 CRITICAL (
AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). The attack works over the network, has low complexity, and needs no user interaction. The scope is changed, with high impact to confidentiality, integrity and availability. - CVSS 4.0: 8.6 HIGH, with exploit maturity rated Proof-of-Concept.
- CVSS 2.0: 9.0, which requires single authentication.
The attacker needs low-level privileges, so exploitation probably requires some authenticated access to the device. The CNA says the exploit "has been disclosed to the public and may be used," and a public write-up is posted on GitHub.
KEV status: CISA's Known Exploited Vulnerabilities catalog has no entry for this CVE, so the supplied data does not confirm active exploitation in the wild. A public proof-of-concept still shortens the time before attacks are likely.
What's Vulnerable
| Vendor | Product | Component | Affected Version |
|---|---|---|---|
| Tenda | AC5 | Wifi Handler (/goform/setWifi) |
02.03.01.111_multi |
The CNA's CPE is cpe:2.3:o:tenda:ac5_firmware:*:*:*:*:*:*:*:*. The public write-up refers to the device as "AC5v3."
Patch Status
The supplied sources do not mention a vendor patch, a fixed firmware version, or a vendor advisory. Because this CVE is not in KEV, CISA has not set a required action or due date.
Until Tenda releases a fix, owners of affected AC5 units should:
- Limit access to the router's management interface.
- Make sure only trusted users have credentials to the device.
- Check Tenda's site for firmware updates.