Executive brief
Tenda G0 and PW201A routers are affected by a security flaw in how they handle certain web-based configuration requests. By sending a specially crafted web request to the device, an attacker can cause the router to crash or become unstable. This results in a denial of service, disrupting internet connectivity and network operations for all connected users.
Technical details
A stack-based buffer overflow exists in the 'TENDA_HTTPD' binary of Tenda G0 and PW201A devices. The vulnerability is located within the Saveqqlist function (called by the L7Im handler at offset 0x42d520), where user-supplied input from the 'qqStr' and 'markStr' HTTP parameters is processed using 'sprintf' without adequate bounds checking. An unauthenticated remote attacker can exploit this by sending a crafted HTTP request containing excessively long strings in these parameters. Successful exploitation leads to a process crash or device instability, resulting in a Denial of Service (DoS).
Affected products
- Tenda G0 v15.11.0.5
- Tenda PW201A V1.0.5
Timeline
- 2026-03-17: other: CVE request submitted to MITRE
- 2026-06-06: disclosed: Public disclosure of vulnerability details
- 2026-06-09: advisory: NVD published CVE-2026-36805