Junglewise Threat Intelligence

CVE-2026-36802: Tenda PW201A buffer overflow in SafeMacFilter

CVE-2026-36802 · Severity: info · CVSS 7.5 · Published 2026-06-09

Technologies: Tenda PW201A. Vendors: Tenda.

Executive brief

The Tenda PW201A, a wireless powerline adapter used to extend home or office networks, contains a security flaw in its web management interface. By sending a specially crafted web request, an attacker can crash the device's management service. This results in a denial of service, making the device's configuration interface unavailable and potentially disrupting network connectivity.

Technical details

A stack-based buffer overflow exists in the TENDA_HTTPD binary of the Tenda PW201A v1.0.5. The vulnerability is located in the SafeMacFilter handler function (address 0x42e6a4), where the 'page' HTTP parameter is retrieved via websGetVar and subsequently passed to sprintf without bounds checking into a fixed-size stack buffer (acStack_120). An unauthenticated remote attacker can exploit this by sending a crafted HTTP request with an overly long 'page' parameter, leading to a process crash and Denial of Service. No patch is currently mentioned in the advisory.

Affected products

  • Tenda PW201A v1.0.5

Timeline

  • 2026-03-17: other: CVE request submitted to MITRE
  • 2026-06-06: disclosed: Public disclosure
  • 2026-06-09: advisory: NVD published date

References

Related threats