Executive brief
The Tenda W15E enterprise router contains a security flaw in its web management interface. By sending a specially crafted web request to the device, an attacker can cause the router to crash or become unresponsive. This results in a denial of service, disrupting internet connectivity and local network operations for all connected users.
Technical details
A stack-based buffer overflow exists in the Tenda W15E v15.11.0.10 firmware within the 'formModifyWebAuthUser' function. The vulnerability is triggered when the 'webAuthUserPwd' and 'webAuthUser' HTTP parameters, retrieved via 'websGetVar', are passed to an unsafe 'sprintf' call without proper bounds checking. An attacker can exploit this by sending a crafted HTTP POST request to the 'modifyWebAuthUser' action with excessively long strings in these parameters. This leads to memory corruption, resulting in a process crash or device instability (Denial of Service). No authentication requirements were specified in the disclosure, suggesting the endpoint may be reachable by unauthenticated network actors.
Affected products
- Tenda W15E v15.11.0.10
Timeline
- 2026-03-18: other: CVE request submitted to MITRE
- 2026-06-06: disclosed: Public disclosure
- 2026-06-09: advisory: NVD published date