Executive brief
The Tenda W20E enterprise-grade wireless router is vulnerable to a security flaw in its web management interface. By sending a specially crafted web request to the device, an attacker can cause the router to crash or become unstable. This results in a denial-of-service condition, disrupting internet connectivity and network operations for all connected users.
Technical details
A stack-based buffer overflow exists in the 'formAddWewifiWhiteUser' function within the Tenda W20E v15.11.0.6 firmware. The vulnerability is triggered when the 'wewifiWhiteUserInfo' HTTP parameter, retrieved via 'websGetVar', is processed using 'strncpy' without adequate bounds checking. Specifically, the code calculates the length of the input up to a newline character and copies it into a fixed-size destination buffer ('temp'). An attacker can exploit this by sending a long string followed by a newline character in a crafted HTTP request to the 'addWewifiWhiteUser' action, leading to a process crash or device instability. While the advisory focuses on Denial of Service, buffer overflows of this nature can sometimes lead to remote code execution.
Affected products
- Tenda (Shenzhen Tenda Technology Co., Ltd) W20E v15.11.0.6
Timeline
- 2026-03-19: other: CVE request submitted to MITRE
- 2026-06-06: disclosed: Public disclosure
- 2026-06-09: advisory: NVD published date