Junglewise Threat Intelligence

CVE-2026-36823: Tenda W20E buffer overflow in formAddWebAuthUser

CVE-2026-36823 · Severity: info · Published 2026-06-09

Technologies: Tenda W20E. Vendors: Tenda.

Executive brief

The Tenda W20E enterprise-grade wireless router is vulnerable to a security flaw in its web management interface. By sending a specially crafted web request to the device, an attacker can cause the router's management service to crash or become unstable. This results in a denial of service, preventing administrators from managing the network and potentially disrupting internet connectivity for connected users.

Technical details

A stack-based buffer overflow exists in the Tenda W20E v15.11.0.6 firmware within the 'formAddWebAuthUser' function. The vulnerability is triggered when the 'webAuthUserInfo' HTTP parameter, retrieved via 'websGetVar', is processed using 'strncpy' without adequate bounds checking. Specifically, the code calculates the length of the string to copy based on the position of a newline character ('\n') using 'strchr', which can be manipulated by an attacker to exceed the destination buffer's capacity. An unauthenticated remote attacker can exploit this by sending a crafted HTTP request to the 'addWebAuthUser' action, leading to a process crash or device instability (Denial of Service).

Affected products

  • Tenda W20E v15.11.0.6

Timeline

  • 2026-03-19: other: CVE request submitted to MITRE
  • 2026-06-06: disclosed: Public disclosure of vulnerability details
  • 2026-06-09: advisory: CVE-2026-36823 published by NVD

References

Related threats