CVE-2026-90689
moderateStack Buffer Overflow in Tenda W20E Router formDelWebAuthWhiteUser
A remotely exploitable stack-based buffer overflow (CWE-121) exists in the formDelWebAuthWhiteUser function of the Tenda W20E router's web management interface, affecting firmware version 15.11.0.61068_1546_841_CN_TDC. An attacker triggers the flaw by sending a crafted request in which the webAuthWhiteUserIndex argument is manipulated to exceed the bounds of a stack buffer; the CVSS 4.0 vector indicates low privileges are required (PR:L), suggesting an authenticated or low-privilege session with the management interface is sufficient. Successful exploitation can crash the device and, given the high confidentiality, integrity, and availability impact ratings (VC:H/VI:H/VA:H), plausibly lead to arbitrary code execution on the router, with a base score of 8.7 (high). Devices affected are Tenda W20E routers—primarily a China-market enterprise/SMB access router—running the listed firmware. There is no evidence of in-the-wild exploitation: the CVE is not in the CISA KEV catalog and no public proof of concept is known.
What to do: Disable WAN-side (remote) access to the router's web management interface and restrict administration to the LAN or a VPN, since exploitation requires only low privileges against the interface. Monitor vendor advisories and apply updated Tenda firmware for the W20E as soon as a fixed version is released—no patched version is identified in current data. Review device logs and uptime for unexpected crashes or suspicious requests targeting formDelWebAuthWhiteUser, and reboot plus credential rotation if compromise is suspected.
| Tenda W20E | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A security flaw has been discovered in Tenda W20E 15.11.0.61068_1546_841_CN_TDC. Impacted is the function formDelWebAuthWhiteUser. Performing a manipulation of the argument webAuthWhiteUserIndex results in stack-based buffer overflow. The attack can be initiated remotely.
- Weakness
- CWE-119, CWE-121
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.