ZeroHour

CVE-2026-90688

moderate

Stack-Based Buffer Overflow in Tenda W20E Router HTTP Handler

CVSS 4.0
7.1 high
EPSS
Published
()
Modified
AI analysis

Tenda W20E routers running firmware 15.11.0.61068_1546_841_CN_TDC contain a stack-based buffer overflow in the formIPMacBindAdd function of the HTTP handler, reachable remotely over the network. The flaw is triggered by supplying an oversized or malformed IPMacBindRule argument to the IP/MAC address-binding feature, which overflows a fixed-length stack buffer. With a CVSS 4.0 score of 7.1 (AV:N/AC:L/PR:L/VA:H), the scored impact is availability — crashing or rebooting the device — though stack overflows of this class can potentially be escalated to code execution depending on the target's memory protections. The PR:L rating means the attacker needs some level of authentication (valid low-privilege credentials or a companion auth-bypass flaw) to reach the vulnerable endpoint. No public proof-of-concept is known, and the CVE is not in CISA's KEV catalog, so there is no evidence of exploitation in the wild.

What to do: Restrict the router's web management interface to the internal LAN or a trusted management network and ensure it is not exposed to the internet. Check Tenda's support site for firmware newer than 15.11.0.61068_1546_841_CN_TDC and upgrade when a patch is released, noting Tenda has historically been slow to fix similar router flaws. Enforce strong, unique admin credentials since exploitation requires low privileges, and monitor the device for unexplained reboots or crashes that could indicate crash attempts.

Affected
Tenda W20E
Estimated exposure
moderatelikely low thousands of internet-exposed devices (roughly 1,000–10,000, mostly on Chinese networks) — The W20E is an enterprise router sold primarily in China (the affected build is a CN firmware), and public internet scan engines such as Shodan/Censys typically show a few thousand exposed Tenda W20E units at any time.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability was identified in Tenda W20E 15.11.0.61068_1546_841_CN_TDC. This issue affects the function formIPMacBindAdd of the component HTTP Handler. Such manipulation of the argument IPMacBindRule leads to stack-based buffer overflow. It is possible to launch the attack remotely.

Weakness
CWE-119, CWE-121
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.