Executive brief
The Tenda G0 router is susceptible to a security flaw that can be triggered by sending a specifically formatted web request. An attacker can exploit this to crash the device's management interface or cause the entire router to become unstable. This results in a denial of service, disrupting network connectivity and administrative access for the organization.
Technical details
A stack-based buffer overflow exists in the 'formPortalAuth' function of the Tenda G0 v15.11.0.5 firmware. The vulnerability is located in the handling of the 'gotoUrl' HTTP parameter, which is retrieved via 'websGetVar' and subsequently passed to 'strcpy' without proper bounds checking into a fixed-size stack buffer (acStack_210). An unauthenticated remote attacker can exploit this by sending a crafted HTTP request with an excessively long string in the 'gotoUrl' parameter. Successful exploitation leads to a crash of the web service or device instability, resulting in a Denial of Service (DoS).
Affected products
- Tenda (Shenzhen Tenda Technology) G0 v15.11.0.5
Timeline
- 2026-03-17: other: CVE request submitted to MITRE
- 2026-06-06: disclosed: Public disclosure of vulnerability details
- 2026-06-09: advisory: NVD publication date