Description
Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the wewifiWhiteUserInfo parameter of the formAddWewifiWhiteUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
Published: 2026-06-09
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a buffer overflow in the formAddWewifiWhiteUser function, triggered by an invalid wewifiWhiteUserInfo parameter. This flaw allows an attacker to overflow a memory buffer and crash the application, resulting in a denial of service. The weakness corresponds to CWE-119 – Buffer Overflow.

Affected Systems

Shenzhen Tenda Technology Co., Ltd provides the Tenda W15E router, firmware version 15.11.0.10, which is affected by this issue.

Risk and Exploitability

The vulnerability is triggered via a crafted HTTP request targeting the formAddWewifiWhiteUser endpoint. No EPSS score is available, and the issue is not listed in CISA KEV. Attackers need only be able to reach the vulnerable HTTP service to force the device into a DoS state. The impact is limited to availability for the device and any services relying on it.

Generated by OpenCVE AI on June 9, 2026 at 21:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and install the latest firmware from Tenda when it becomes available, ensuring the buffer overflow fix is included.
  • Disable or restrict remote HTTP access to the formAddWewifiWhiteUser endpoint to prevent exploitation over the network.
  • Configure network firewalls or the device’s rate‑limiting features to block repeated or unusually large requests to the vulnerable endpoint and monitor logs for DoS activity.

Generated by OpenCVE AI on June 9, 2026 at 21:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 09 Jun 2026 22:00:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in Tenda W15E Leading to Denial of Service via HTTP
Weaknesses CWE-119

Tue, 09 Jun 2026 18:45:00 +0000

Type Values Removed Values Added
Description Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the wewifiWhiteUserInfo parameter of the formAddWewifiWhiteUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-06-09T18:12:49.050Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-36816

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-06-09T19:17:47.250

Modified: 2026-06-09T19:35:05.693

Link: CVE-2026-36816

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-09T21:45:05Z

Weaknesses