CVE-2026-5036

A vulnerability was found in Tenda 4G06 04.06.01.29. This vulnerability affects the function fromDhcpListClient of the file /goform/DhcpListClient of the component Endpoint. Performing a manipulation of the argument page results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made public and could be used.
References
Link Resource
https://github.com/Kiciot/cve/issues/1 Exploit Issue Tracking
https://vuldb.com/submit/778625 Permissions Required VDB Entry
https://vuldb.com/vuln/353962 Third Party Advisory VDB Entry
https://vuldb.com/vuln/353962/cti Permissions Required VDB Entry
https://www.tenda.com.cn/ Product
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tenda:4g06_firmware:04.06.01.29:*:*:*:*:*:*:*
cpe:2.3:h:tenda:4g06:3.0:*:*:*:*:*:*:*

History

17 Jun 2026, 10:58

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad se encontró en Tenda 4G06 04.06.01.29. Esta vulnerabilidad afecta a la función fromDhcpListClient del archivo /goform/DhcpListClient del componente Endpoint. Realizar una manipulación del argumento page provoca un desbordamiento de búfer basado en pila. El ataque puede iniciarse de forma remota. El exploit se ha hecho público y podría ser utilizado.
References () https://vuldb.com/vuln/353962/cti - VDB Entry, Permissions Required () https://vuldb.com/vuln/353962/cti - Permissions Required, VDB Entry

30 Mar 2026, 18:58

Type Values Removed Values Added
CPE cpe:2.3:o:tenda:4g06_firmware:04.06.01.29:*:*:*:*:*:*:*
cpe:2.3:h:tenda:4g06:3.0:*:*:*:*:*:*:*
References () https://github.com/Kiciot/cve/issues/1 - () https://github.com/Kiciot/cve/issues/1 - Exploit, Issue Tracking
References () https://vuldb.com/submit/778625 - () https://vuldb.com/submit/778625 - Permissions Required, VDB Entry
References () https://vuldb.com/vuln/353962 - () https://vuldb.com/vuln/353962 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/353962/cti - () https://vuldb.com/vuln/353962/cti - VDB Entry, Permissions Required
References () https://www.tenda.com.cn/ - () https://www.tenda.com.cn/ - Product
First Time Tenda
Tenda 4g06 Firmware
Tenda 4g06

29 Mar 2026, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-29 08:15

Updated : 2026-06-17 10:58


NVD link : CVE-2026-5036

Mitre link : CVE-2026-5036

CVE.ORG link : CVE-2026-5036


JSON object : View

Products Affected

tenda

  • 4g06
  • 4g06_firmware
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-121

Stack-based Buffer Overflow