Executive brief
A vulnerability exists in the Tenda PW201A wireless powerline adapter, a device used to extend network coverage through electrical wiring. An attacker can exploit this flaw to crash the device or make it unstable by sending a specially crafted web request. This results in a loss of internet connectivity and network services for users relying on the affected hardware.
Technical details
A stack-based buffer overflow exists in the TENDA_HTTPD binary of Tenda PW201A v1.0.5. The vulnerability is located in the qossetting function (offset 0x42e1c4), which is registered as a web form handler. The function retrieves the 'page' parameter using websGetVar and subsequently passes it to sprintf without length validation to populate a fixed-size stack buffer (acStack_120). An unauthenticated remote attacker can trigger this overflow by sending a crafted HTTP request with an excessively long string in the 'page' parameter, resulting in a process crash or device instability.
Affected products
- Tenda PW201A v1.0.5
Timeline
- 2026-03-17: other: CVE request submitted to MITRE
- 2026-06-06: disclosed: Public disclosure of vulnerability details
- 2026-06-09: advisory: NVD published date