Impact
A stack-based buffer overflow exists in the lstAdd function of the /goform/editQos component on Tenda W20E routers. Manipulating the qosListConnecttedNum argument can overwrite stack memory, potentially allowing an attacker to execute arbitrary code. The vulnerability is classified as CWE-119 and CWE-121 and can be exploited remotely by sending crafted HTTP requests.
Affected Systems
The flaw affects the Tenda W20E router firmware 15.11.0.6(1068_1546_841)_CN_TDC. Only this specific firmware revision is known to be vulnerable; newer releases may already contain a fix.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity risk. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, but the exploit is publicly available and can be launched from outside the network. The attack typically involves sending a malformed request to /goform/editQos, causing a stack overflow that could lead to remote code execution.
OpenCVE Enrichment