Executive brief
A vulnerability has been identified in the Tenda AC15 wireless router, a device used to provide Wi-Fi and networking for homes and small offices. An attacker can exploit this flaw to crash the device or potentially take full control of it by sending specially crafted password change requests. This could lead to a total loss of internet connectivity, unauthorized access to the network, or the interception of user data.
Technical details
A stack-based buffer overflow vulnerability exists in the Tenda AC15 router (firmware version 15.03.05.18) within the 'websGetVar' function of the '/goform/SysToolChangePwd' component. The issue stems from improper validation of the 'oldPwd', 'newPwd', and 'cfmPwd' arguments, allowing an attacker to overwrite the stack. This attack can be executed remotely over the network, though it typically requires low-level authentication (PR:L). Successful exploitation can lead to remote code execution (RCE) or a complete system crash (DoS). A public exploit is currently available.
Affected products
- Tenda AC15 15.03.05.18
Timeline
- 2026-04-09: disclosed
- 2026-04-09: advisory