Junglewise Threat Intelligence

CVE-2026-90688: Tenda W20E stack buffer overflow in formIPMacBindAdd

CVE-2026-90688 · Severity: medium · CVSS 6.5 · Published 2026-09-14

Technologies: Tenda W20E. Vendors: Tenda.

Executive brief

The Tenda W20E is a Wi-Fi router used by consumers and small businesses to provide network connectivity. A flaw in the router's web management interface allows remote attackers to send specially crafted network requests that corrupt the router's memory, causing the web management service to crash and disrupting access to the router's administration panel.

Technical details

The vulnerability is a stack-based buffer overflow in the formIPMacBindAdd HTTP handler of the Tenda W20E router. The vulnerable component fails to perform length validation on the IPMacBindRule parameter before copying it into fixed-size stack buffers using unbounded strcpy operations (CWE-121). An attacker on the network can remotely send an oversized IPMacBindRule value through the HTTP handler to trigger stack memory corruption. The resulting overflow causes the web management process to crash, causing denial of service of the router administration interface. The vulnerability affects firmware version 15.11.0.61068_1546_841_CN_TDC and potentially other versions.

Affected products

  • Tenda W20E 15.11.0.61068_1546_841_CN_TDC

Timeline

  • 2026-09-14: disclosed

References

Related threats