Junglewise Threat Intelligence

CVE-2026-6015: Tenda AC9 stack-based buffer overflow in QuickIndex

CVE-2026-6015 · Severity: high · CVSS 8.8 · Published 2026-04-10

Technologies: Tenda Ac9 Firmware, Tenda Ac9. Vendors: Tenda.

Executive brief

A security vulnerability has been identified in the Tenda AC9 router, a device used to provide wireless internet in homes and small offices. An attacker could exploit this flaw to disrupt the router's operations or potentially take control of the device. This could lead to a total loss of internet connectivity or unauthorized access to the network traffic passing through the router.

Technical details

A stack-based buffer overflow vulnerability exists in the Tenda AC9 router firmware version 15.03.02.13. The flaw is located within the 'formQuickIndex' function in the '/goform/QuickIndex' file, which serves as a POST request handler. An attacker can trigger the overflow by providing a specially crafted, overly long string to the 'PPPOEPassword' argument. While the attack requires low-level authentication (PR:L), it can be executed remotely over the network. Successful exploitation could allow for remote code execution (RCE) or a denial of service (DoS) condition. Public exploit code has been disclosed.

Affected products

  • Tenda AC9 15.03.02.13

Timeline

  • 2026-04-10: disclosed: Vulnerability disclosed and CVE assigned
  • 2026-04-10: advisory

References

Related threats