Executive brief
The Tenda W15E is a wireless router used for business and home networking. A security flaw in the device's portal authentication feature allows an attacker to crash the router by sending a specially crafted web request. This can lead to a complete loss of internet connectivity and network services for all connected users until the device is restarted.
Technical details
A stack-based buffer overflow exists in the Tenda W15E v15.11.0.10 firmware within the 'formPortalAuth' function. The vulnerability is caused by the unsafe use of 'strcpy' when processing the 'gotoUrl' HTTP parameter retrieved via 'websGetVar'. An unauthenticated remote attacker can exploit this by sending a crafted HTTP request to the 'portalAuth' endpoint with an excessively long string in the 'gotoUrl' parameter. Successful exploitation results in a process crash or device instability, leading to a Denial of Service (DoS).
Affected products
- Tenda W15E v15.11.0.10
Timeline
- 2026-03-18: other: CVE request submitted to MITRE
- 2026-06-06: disclosed: Public disclosure of vulnerability details
- 2026-06-09: advisory: NVD publication date