Executive brief
The Tenda W15E enterprise router contains a security flaw in its web management interface. By sending a specially crafted web request, an attacker can crash the device's management service. This results in a denial of service, preventing administrators from managing the network and potentially disrupting internet connectivity for the business.
Technical details
A stack-based buffer overflow exists in the Tenda W15E v15.11.0.10 firmware within the 'formCropAndSetWewifiPic' function. The vulnerability is caused by the unsafe use of 'sprintf' when processing the 'picCropName' HTTP parameter retrieved via 'websGetVar'. An attacker can trigger the overflow by sending a crafted HTTP request to the affected CGI endpoint with an excessively long string in the 'picCropName' parameter. This results in a process crash or device instability, leading to a Denial of Service (DoS). No patch has been confirmed in the provided advisory.
Affected products
- Tenda W15E v15.11.0.10
Timeline
- 2026-03-18: other: CVE request submitted to MITRE
- 2026-06-06: disclosed: Public disclosure
- 2026-06-09: advisory: NVD published date