Description
Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain a buffer overflow in the portalAuth parameter of the formPortalAuth function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
Published: 2026-06-09
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 contains a buffer overflow in the portalAuth parameter of the formPortalAuth function. The flaw can be triggered by a crafted HTTP request, causing the firmware to crash and resulting in a denial of service. This vulnerability is an example of improper bounds checking leading to memory corruption, classified under the standard buffer overflow weakness. An attacker who can send a malicious request to the device can render the web portal or the device entirely unresponsive, disrupting service availability for all users on that network.

Affected Systems

Tenda G0 routers running firmware version v15.11.0.5 are affected. Only the specified version is listed; no other versions or vendor products are indicated in the advisory.

Risk and Exploitability

The exploit requires remote access to the device's web interface via HTTP, suggesting a remote attack vector. No CVSS score is supplied, but the lack of EPSS data means the current exploitation probability is unknown. The vulnerability is not listed in CISA KEV, indicating no known public exploits. However, because a simple crafted HTTP request triggers the overflow, an attacker could easily trigger the denial of service if the device is exposed to untrusted networks. Administrators should treat this as a medium‑to‑high risk if the device provides critical services.

Generated by OpenCVE AI on June 9, 2026 at 21:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Tenda G0 firmware to a version that does not contain the buffer overflow, as released by the vendor.
  • If unable to upgrade immediately, restrict access to the device's web interface by placing it behind a firewall or disabling it entirely.
  • Monitor the device for repeated oversized or malformed HTTP requests and reset it automatically if a crash is detected.

Generated by OpenCVE AI on June 9, 2026 at 21:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 09 Jun 2026 22:15:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in PortalAuth Parameter Leading to Denial of Service in Tenda G0 Device
Weaknesses CWE-120
CWE-122

Tue, 09 Jun 2026 18:45:00 +0000

Type Values Removed Values Added
Description Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain a buffer overflow in the portalAuth parameter of the formPortalAuth function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-06-09T18:12:40.551Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-36799

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-06-09T19:17:45.487

Modified: 2026-06-09T19:35:05.693

Link: CVE-2026-36799

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-09T22:00:19Z

Weaknesses