<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:tenda:ac5:02.03.01.111_multi:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3atendaac502.03.01.111_multi/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 06 Oct 2026 08:53:33 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3atendaac502.03.01.111_multi/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Stack-Based Buffer Overflow in Tenda AC5</title><link>https://feed.craftedsignal.io/briefs/2026-10-tenda-ac5-overflow/</link><pubDate>Tue, 06 Oct 2026 08:53:33 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-tenda-ac5-overflow/</guid><description>A critical remote stack-based buffer overflow vulnerability in the Tenda AC5 router allows unauthenticated attackers to execute arbitrary code via the wifiPwd parameter.</description><content:encoded><![CDATA[<p>A critical stack-based buffer overflow vulnerability has been identified in Tenda AC5 router firmware version 02.03.01.111_multi. The flaw is located within the Wifi Handler component, specifically within the '/goform/setWifi' endpoint. An unauthenticated remote attacker can trigger this vulnerability by sending a maliciously crafted 'wifiPwd' argument to the device. Exploitation of this flaw allows for arbitrary code execution or a denial of service condition. Given that the exploit code has been disclosed to the public, there is a high risk of active exploitation. Defenders should monitor for unexpected traffic directed at the router's web management interface and evaluate exposure of these devices.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability results in full device compromise, allowing an attacker to execute arbitrary code with the privileges of the web management process. This can lead to persistent unauthorized access, lateral movement within the local network, or persistent denial of service. The vulnerability is rated at a CVSS v3.1 base score of 9.9, reflecting its critical nature and ease of remote exploitation without authentication.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Identify all Tenda AC5 devices within the environment, specifically those running firmware version 02.03.01.111_multi.</li>
<li>Implement access control lists (ACLs) on the perimeter firewall to restrict access to the web management interface of identified Tenda devices from untrusted networks.</li>
<li>Monitor network traffic logs for anomalous HTTP POST requests directed at '/goform/setWifi'.</li>
<li>Monitor for firmware update availability from Tenda and apply patches to all vulnerable AC5 devices as soon as they are released.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">threat</category></item></channel></rss>