Junglewise Threat Intelligence

CVE-2026-36805: Tenda G0 and PW201A buffer overflow in Saveqqlist function

CVE-2026-36805 · Severity: info · CVSS 7.5 · Published 2026-06-09

Technologies: Tenda PW201A, Tenda G0. Vendors: Tenda.

Executive brief

Tenda G0 and PW201A routers are affected by a security flaw in how they handle certain web-based configuration requests. By sending a specially crafted web request to the device, an attacker can cause the router to crash or become unstable. This results in a denial of service, disrupting internet connectivity and network operations for all connected users.

Technical details

A stack-based buffer overflow exists in the 'TENDA_HTTPD' binary of Tenda G0 and PW201A devices. The vulnerability is located within the Saveqqlist function (called by the L7Im handler at offset 0x42d520), where user-supplied input from the 'qqStr' and 'markStr' HTTP parameters is processed using 'sprintf' without adequate bounds checking. An unauthenticated remote attacker can exploit this by sending a crafted HTTP request containing excessively long strings in these parameters. Successful exploitation leads to a process crash or device instability, resulting in a Denial of Service (DoS).

Affected products

  • Tenda G0 v15.11.0.5
  • Tenda PW201A V1.0.5

Timeline

  • 2026-03-17: other: CVE request submitted to MITRE
  • 2026-06-06: disclosed: Public disclosure of vulnerability details
  • 2026-06-09: advisory: NVD published CVE-2026-36805

References

Related threats