Description
Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the picCropName parameter of the formCropAndSetWewifiPic function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
Published: 2026-06-09
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A buffer overflow occurs in the picCropName parameter within the formCropAndSetWewifiPic function of the Tenda W20E router. The flaw allows an attacker to supply an overly long input string that overflows the designated buffer, leading to a crash of the affected process or the entire system, which in turn results in a denial of service. The primary impact is service disruption, and it does not directly lead to arbitrary code execution or data theft.

Affected Systems

The vulnerability affects Shenzhen Tenda Technology’s Tenda W20E router running firmware version 15.11.0.6. No other affected versions are listed in the publicly available CVE data, so older or newer firmware may not be impacted, but the uncertainty advises caution.

Risk and Exploitability

The CVSS score is not disclosed in the information provided, and the EPSS score is unavailable. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the most likely attack vector is a crafted HTTP request sent over the network to the router’s web interface, leveraging the formCropAndSetWewifiPic endpoint. Because the exploit requires network connectivity to the device, it is considered a local‑internal risk, but it could also be leveraged by external actors if the device is exposed to the Internet. The risk is primarily high due to the potential for disrupting network services, especially in environments where the router is a critical gateway.

Generated by OpenCVE AI on June 9, 2026 at 21:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update device firmware to the latest version from Shenzhen Tenda Technology
  • Disable or remove the formCropAndSetWewifiPic functionality, if possible
  • Implement network‑level restrictions to limit HTTP access to the device

Generated by OpenCVE AI on June 9, 2026 at 21:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 09 Jun 2026 22:00:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in Tenda W20E Form Crop Function Causes DoS
Weaknesses CWE-120

Tue, 09 Jun 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-121
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Jun 2026 18:45:00 +0000

Type Values Removed Values Added
Description Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the picCropName parameter of the formCropAndSetWewifiPic function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-06-09T19:32:43.016Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-36821

cve-icon Vulnrichment

Updated: 2026-06-09T19:32:39.458Z

cve-icon NVD

Status : Deferred

Published: 2026-06-09T19:17:47.817

Modified: 2026-06-09T21:17:11.353

Link: CVE-2026-36821

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-09T21:45:05Z

Weaknesses