Description
A flaw has been found in Tenda W20E 15.11.0.6. This issue affects the function formPortalAuth of the file /goform/PortalAuth of the component Web Management Interface. Executing a manipulation of the argument gotoUrl can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been published and may be used.
Published: 2026-06-08
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a stack-based buffer overflow in Tenda W20E’s Web Management Interface, specifically triggered by a crafted gotoUrl argument sent to the formPortalAuth function at the /goform/PortalAuth endpoint. Manipulating this parameter can corrupt the stack; based on the nature of stack overflows, such corruption might allow an attacker to execute arbitrary code, although the CVE text does not explicitly confirm this outcome.

Affected Systems

The flaw affects the Tenda W20E router running firmware version 15.11.0.6. The vulnerability is present in the web management portal exposed through the /goform/PortalAuth endpoint.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity. EPSS information is not available, but the CVE notes that a public exploit has been published and can be triggered remotely, suggesting that exploitation is possible. The vulnerability is not listed in CISA’s KEV catalog at this time. The remote attack vector and the high severity level make it a priority for remediation.

Generated by OpenCVE AI on June 8, 2026 at 16:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Acquire and install any Tenda firmware update that resolves the formPortalAuth buffer overflow; contact Tenda support for an official patch if one is not publicly available.
  • If a patch is not available, block external access to the /goform/PortalAuth endpoint, permitting connections only from trusted internal hosts.
  • Implement network segmentation and firewall rules to expose the router’s web management interface solely to the internal network or a dedicated management VLAN.

Generated by OpenCVE AI on June 8, 2026 at 16:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 08 Jun 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 08 Jun 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Tenda w20e
Vendors & Products Tenda w20e

Mon, 08 Jun 2026 15:45:00 +0000

Type Values Removed Values Added
Description A flaw has been found in Tenda W20E 15.11.0.6. This issue affects the function formPortalAuth of the file /goform/PortalAuth of the component Web Management Interface. Executing a manipulation of the argument gotoUrl can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been published and may be used.
Title Tenda W20E Web Management PortalAuth formPortalAuth stack-based overflow
First Time appeared Tenda
Tenda w20e Firmware
Weaknesses CWE-119
CWE-121
CPEs cpe:2.3:o:tenda:w20e_firmware:*:*:*:*:*:*:*:*
Vendors & Products Tenda
Tenda w20e Firmware
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Tenda W20e W20e Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-06-08T16:36:03.017Z

Reserved: 2026-06-07T16:06:42.495Z

Link: CVE-2026-11523

cve-icon Vulnrichment

Updated: 2026-06-08T16:26:42.445Z

cve-icon NVD

Status : Received

Published: 2026-06-08T16:16:37.113

Modified: 2026-06-08T17:16:39.790

Link: CVE-2026-11523

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-08T17:00:16Z

Weaknesses