Executive brief
A vulnerability exists in the Tenda W20E enterprise router, a device used to manage business network connectivity. An attacker can exploit this flaw to crash the router's management interface or potentially take full control of the device. This could lead to network downtime, unauthorized access to network settings, or a foothold for further attacks on the corporate network.
Technical details
A stack-based buffer overflow vulnerability exists in the Tenda W20E enterprise router (version 15.11.0.6) within the 'modifyWifiFilterRules' function of the web management interface. The issue stems from the use of the unsafe 'sprintf' function when processing the 'wifiFilterListRemark' parameter in HTTP POST requests to '/goform/modifyWifiFilterRules'. A remote attacker with low privileges (authenticated to the web interface) can provide an overly long string to overflow the stack buffer. This can result in a denial-of-service (DoS) condition through a service crash or potentially lead to remote code execution (RCE). A public exploit has been disclosed.
Affected products
- Tenda W20E 15.11.0.6
Timeline
- 2026-06-08: disclosed: Vulnerability and exploit details made public.
- 2026-06-08: advisory: NVD published the CVE record.