Two high-severity vulnerabilities have been disclosed in Tenda router firmware, affecting Tenda AC5 version 15.03.06.47 and Tenda AC6 version 15.03.05.16. The flaws reside in the formQuickIndex function behind the /goform/QuickIndex POST request handler, where improper handling of the PPPOEPassword parameter can trigger a stack-based buffer overflow. Both issues are tracked as CVE-2026-4903 for AC5 and CVE-2026-4961 for AC6.
The vulnerabilities are described as remotely exploitable, with public exploits available, raising the risk of real-world attacks against exposed devices. The entries map the weaknesses to CWE-119 and CWE-121, and their published CVSS vectors indicate high impact across confidentiality, integrity, and availability, making these flaws significant for organizations or users still operating the affected firmware.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
A separate CVE entry was recorded for Tenda AC6 firmware 15.03.05.16 involving a stack-based buffer overflow in the same formQuickIndex function of the /goform/QuickIndex POST handler through the PPPOEPassword argument. The vulnerability was described as remotely exploitable with a public exploit available and classified under CWE-119 and CWE-121.
A CVE entry for Tenda AC5 firmware 15.03.06.47 was recorded describing a stack-based buffer overflow in the formQuickIndex function of the /goform/QuickIndex POST handler via the PPPOEPassword argument. The flaw was noted as remotely exploitable, with a public exploit available, and mapped to CWE-119 and CWE-121.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.