Impact
The vulnerability is a stack-based buffer overflow in Tenda W20E’s Web Management Interface, specifically triggered by a crafted gotoUrl argument sent to the formPortalAuth function at the /goform/PortalAuth endpoint. Manipulating this parameter can corrupt the stack; based on the nature of stack overflows, such corruption might allow an attacker to execute arbitrary code, although the CVE text does not explicitly confirm this outcome.
Affected Systems
The flaw affects the Tenda W20E router running firmware version 15.11.0.6. The vulnerability is present in the web management portal exposed through the /goform/PortalAuth endpoint.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. EPSS information is not available, but the CVE notes that a public exploit has been published and can be triggered remotely, suggesting that exploitation is possible. The vulnerability is not listed in CISA’s KEV catalog at this time. The remote attack vector and the high severity level make it a priority for remediation.
OpenCVE Enrichment