Two high-severity vulnerabilities have been disclosed in Tenda AC15 router firmware, both involving stack-based buffer overflows in web management handlers that are reachable through crafted POST requests. CVE-2026-4975 affects firmware version 15.03.05.19 in the formSetCfm function behind the /goform/setcfm endpoint, where manipulation of the funcpara1 parameter can corrupt memory and potentially allow remote compromise of the device.
A second flaw, CVE-2026-5830, affects Tenda AC15 version 15.03.05.18 in the websGetVar function used by /goform/SysToolChangePwd; crafted oldPwd, newPwd, or cfmPwd values can trigger another stack-based overflow. Both issues are classified under CWE-119 and CWE-121, carry high-impact severity ratings for confidentiality, integrity, and availability, and have been publicly disclosed, with the latter report explicitly noting that a public exploit is available.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
VulDB received CVE-2026-5830 for a Tenda AC15 15.03.05.18 vulnerability in the /goform/SysToolChangePwd endpoint on April 9, 2026. The issue involves stack-based buffer overflow via the oldPwd, newPwd, or cfmPwd parameters in websGetVar, and the entry states that a public exploit is available.
A vulnerability affecting Tenda AC15 firmware 15.03.05.19 was recorded as CVE-2026-4975. The flaw in the /goform/setcfm POST handler's formSetCfm function can be triggered via the funcpara1 argument to cause a remotely exploitable stack-based buffer overflow, and it had already been publicly disclosed by the time of publication.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.