Description
Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain a stack overflow in the IPMacBindRuleIp parameter of the formIPMacBindModify function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
Published: 2026-06-09
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a stack overflow in the IPMacBindRuleIp parameter of the formIPMacBindModify function in Tenda G0 firmware. When an attacker sends a crafted HTTP request, the overflow corrupts stack memory and causes the device to crash, resulting in a denial of service. The flaw stems from improper bounds checking – a classic buffer overflow scenario.

Affected Systems

Shenzhen Tenda Technology Co., Ltd Tenda G0 version 15.11.0.5 is affected. No other versions or products were listed.

Risk and Exploitability

The attack vector is remote over HTTP, allowing any unauthenticated user on the network or internet if the device is exposed to attack. The CVSS score is not provided, and EPSS is unavailable, but the lack of a security fix and the possibility of widespread DoS keep the risk relatively high. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on June 9, 2026 at 21:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Tenda G0 firmware to the latest released version that contains the remediation for the stack overflow.
  • If a firmware update cannot be applied immediately, configure a network firewall or reverse proxy to block or rate‑limit the formIPMacBindModify endpoint until a patch is installed.
  • Continuously monitor device logs and network traffic for signs of DoS activity originating from suspicious HTTP requests.

Generated by OpenCVE AI on June 9, 2026 at 21:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 09 Jun 2026 22:15:00 +0000

Type Values Removed Values Added
Title Stack Overflow in Tenda G0 IPMacBind Rule Function Causing DoS
Weaknesses CWE-119

Tue, 09 Jun 2026 18:45:00 +0000

Type Values Removed Values Added
Description Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain a stack overflow in the IPMacBindRuleIp parameter of the formIPMacBindModify function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-06-09T18:12:31.451Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-36797

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-06-09T19:17:45.183

Modified: 2026-06-09T19:35:05.693

Link: CVE-2026-36797

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-09T22:00:19Z

Weaknesses