Junglewise Threat Intelligence

CVE-2026-11523: Tenda W20E stack-based buffer overflow in formPortalAuth

CVE-2026-11523 · Severity: high · CVSS 8.8 · Published 2026-06-08

Technologies: Tenda W20E. Vendors: Tenda.

Executive brief

A security vulnerability has been identified in the Tenda W20E enterprise router, a device used to manage business network traffic. An attacker can exploit this flaw to crash the router or potentially take full control of the device with administrative privileges. This could lead to unauthorized access to the internal network, interception of data, or a complete disruption of internet services for the organization.

Technical details

A stack-based buffer overflow exists in the 'formPortalAuth' function within the '/goform/PortalAuth' endpoint of the Tenda W20E (version 15.11.0.6) web management interface. The vulnerability is caused by the unsafe use of the 'strcpy' function when processing the 'gotoUrl' parameter, which is copied into a fixed-size 256-byte stack buffer without length validation. A remote attacker with low privileges can provide an overly long string to overwrite the saved Link Register (LR), leading to a service crash or arbitrary code execution with root privileges. A public exploit has been disclosed.

Affected products

  • Tenda W20E 15.11.0.6

Timeline

  • 2026-06-08: disclosed: Vulnerability published via VulDB and NVD

References

Related threats