Executive brief
The Tenda W20E is a wireless router used for enterprise and small business networking. A security flaw in how the device handles web authentication settings allows an attacker to crash the router by sending a specially crafted web request. This results in a denial-of-service, cutting off internet access and network connectivity for all connected users until the device is recovered.
Technical details
A stack-based buffer overflow exists in the 'formAddWebAuthWhiteUser' function of the Tenda W20E v15.11.0.6 firmware. The vulnerability is triggered when the 'webAuthWhiteUserInfo' HTTP parameter, retrieved via 'websGetVar', is processed using 'strncpy' without adequate bounds checking. Specifically, the code calculates the length of the string to copy based on the position of a newline character ('\n') using 'strchr', allowing an attacker to provide a string longer than the destination buffer 'temp'. A remote attacker can exploit this by sending a crafted HTTP request to the 'addWebAuthWhiteUser' action, resulting in a process crash or device instability (Denial of Service).
Affected products
- Tenda W20E v15.11.0.6
Timeline
- 2026-03-19: other: CVE request submitted to MITRE
- 2026-06-06: disclosed: Public disclosure
- 2026-06-09: advisory: NVD published date