Junglewise Threat Intelligence

CVE-2026-6016: Tenda AC9 stack overflow in WizardHandle decodePwd

CVE-2026-6016 · Severity: high · CVSS 8.8 · Published 2026-04-10

Technologies: Tenda Ac9 Firmware, Tenda Ac9. Vendors: Tenda.

Executive brief

A vulnerability exists in the Tenda AC9 router, a device used to provide wireless internet connectivity in homes and small offices. An attacker can exploit this flaw to cause a system crash or potentially take control of the device by sending a specially crafted web request. This could lead to a total loss of internet availability or unauthorized access to the local network.

Technical details

A stack-based buffer overflow vulnerability exists in the Tenda AC9 router (firmware version 15.03.02.13). The flaw is located within the decodePwd function of the /goform/WizardHandle file, which serves as a POST request handler. An attacker can trigger the overflow by manipulating the 'WANS' argument. This is a remote attack that requires low privileges (authenticated access). Successful exploitation can lead to remote code execution (RCE) or a denial of service (DoS) condition. Public exploit code is reportedly available.

Affected products

  • Tenda AC9 15.03.02.13

Timeline

  • 2026-04-10: disclosed
  • 2026-04-10: advisory

References

Related threats