Junglewise Threat Intelligence

CVE-2026-36816: Tenda W15E buffer overflow in formAddWewifiWhiteUser

CVE-2026-36816 · Severity: info · CVSS 7.5 · Published 2026-06-09

Technologies: Tenda W15E. Vendors: Tenda.

Executive brief

The Tenda W15E is a wireless router used for business and home networking. A security flaw in how the router handles specific web requests allows an attacker to crash the device remotely. This can lead to a complete loss of internet connectivity and network services until the device is manually restarted.

Technical details

A stack-based buffer overflow exists in the Tenda W15E router, specifically within the 'formAddWewifiWhiteUser' function of the web management interface. The vulnerability is triggered when the 'wewifiWhiteUserInfo' HTTP parameter is processed. The code uses 'websGetVar' to retrieve the parameter and subsequently performs a 'strncpy' operation into a fixed-size buffer ('temp') based on the position of a newline character ('\n') without adequate bounds checking. An unauthenticated attacker can exploit this by sending a crafted HTTP request with an excessively long string followed by a newline, leading to a process crash or device instability (Denial of Service).

Affected products

  • Tenda W15E v15.11.0.10

Timeline

  • 2026-03-18: other: CVE request submitted to MITRE
  • 2026-06-06: disclosed: Public disclosure of vulnerability details
  • 2026-06-09: advisory: NVD publication date

References

Related threats