Junglewise Threat Intelligence

CVE-2026-11522: Tenda W20E stack overflow in formSetPortMirror

CVE-2026-11522 · Severity: high · CVSS 8.8 · Published 2026-06-08

Technologies: Tenda W20E. Vendors: Tenda.

Executive brief

A security vulnerability has been identified in the Tenda W20E enterprise router, a device used to manage business network traffic. An attacker can exploit this flaw to cause the router to crash or potentially take full control of the device. This could lead to significant network downtime, unauthorized access to internal communications, or a foothold for further attacks on the corporate network.

Technical details

A stack-based buffer overflow exists in the Tenda W20E router (firmware version 15.11.0.6) within the 'formSetPortMirror' function of the '/goform/setPortMirror' endpoint. The vulnerability is caused by the unsafe use of 'sprintf' when processing the user-supplied 'portMirrorMirroredPorts' parameter, which is copied into a fixed-size 256-byte stack buffer without adequate bounds checking. An authenticated attacker can provide a specially crafted string longer than 256 bytes to overwrite the saved Link Register (LR) on the stack. This can result in a service crash (DoS) or remote code execution (RCE). A public exploit (PoC) is available.

Affected products

  • Tenda W20E 15.11.0.6

Timeline

  • 2026-06-08: disclosed: Vulnerability published and CVE assigned

References

Related threats