


Perceptive Security
SOC/SIEM Consultancy

A vulnerability was found in Tenda 4G06 04.06.01.29. This vulnerability affects the function fromDhcpListClient of the file /goform/DhcpListClient of the compon…
Published:
28 maart 2026 om 23:00:00
Alert date:
29 maart 2026 om 09:00:37
Source:
nvd.nist.gov
Mobile & IoT, Network Infrastructure
A stack-based buffer overflow vulnerability was discovered in Tenda 4G06 router firmware version 04.06.01.29. The vulnerability affects the fromDhcpListClient function in the /goform/DhcpListClient endpoint component. An attacker can exploit this by manipulating the page argument remotely. The vulnerability allows for stack-based buffer overflow attacks that can be initiated from a remote location. Public exploits are available, making this a high-risk vulnerability for affected devices.
Technical details
Mitigation steps:
Affected products:
Tenda 4G06
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-5036
https://github.com/Kiciot/cve/issues/1
https://vuldb.com/submit/778625
https://vuldb.com/vuln/353962
https://vuldb.com/vuln/353962/cti
https://www.tenda.com.cn/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
