Impact
The vulnerability is a stack-based buffer overflow triggered by the wifiFilterListRemark argument in the modifyWifiFilterRules function of Tenda W20E’s Web Management Interface. A malformed input can corrupt the stack, potentially allowing an attacker to execute arbitrary code or crash the device. This flaw is accessible remotely via the web interface and has been publicly disclosed for use in exploitation attempts. The impact spans confidentiality, integrity, and availability, as arbitrary code execution can compromise the entire router and its connected network.
Affected Systems
Tenda W20E firmware 15.11.0.6 is affected. Only this specific model and version lists the vulnerable modifyWifiFilterRules function. No other Tenda models or firmware releases are currently known to be vulnerable.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. No EPSS score is available, but the existence of a public exploit and remote access capability raise the likelihood of attack. The vulnerability is not listed in CISA KEV, but the remote and high impact nature means it should be treated as a serious threat. An adversary can prepare a payload that overflows the buffer and then execute arbitrary code, leading to full takeover of the router or denial of service. Attackers require network access to the router’s management interface, which may be exposed to the internet or internal networks.
OpenCVE Enrichment