Executive brief
The Tenda W20E enterprise-grade router is vulnerable to a security flaw that can be triggered by sending a specifically formatted web request. An attacker can exploit this to crash the device, leading to a total loss of internet connectivity and network services for all connected users. This results in a denial-of-service condition that requires a manual restart or intervention to restore operations.
Technical details
A stack-based buffer overflow exists in the Tenda W20E v15.11.0.6 firmware within the 'formDelStaState' function. The vulnerability is triggered when the 'macAddr' HTTP parameter, retrieved via 'websGetVar', is passed to 'init_wl_policy_list'. Inside this function, a 'memcpy' operation uses a source string derived from 'strtok' without adequate bounds checking, copying up to 0x20 bytes into a destination buffer that can be overrun if the input string (e.g., a long sequence of characters followed by a comma) exceeds expected lengths. A remote attacker can exploit this by sending a crafted HTTP request to the 'delStaState' action, resulting in a process crash or device instability (Denial of Service).
Affected products
- Tenda W20E v15.11.0.6
Timeline
- 2026-03-19: other: CVE request submitted to MITRE
- 2026-06-06: disclosed: Public disclosure
- 2026-06-09: advisory: NVD published date