Description
Buffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782) allows an attacker to execute arbitrary code. This is an incomplete fix for CVE-2025-44867 and CVE-2026-36819
Published: 2026-08-17
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a buffer overflow in the Tenda W20E router firmware version 16.01.0.6(2782). The flaw enables an attacker to execute arbitrary code on the device, potentially compromising its confidentiality, integrity, and availability, and allowing further exploitation of the network the router serves.

Affected Systems

Tenda W20E wireless router running firmware version 16.01.0.6(2782). The vulnerability is an incomplete fix for earlier issues, but only this specific build is affected.

Risk and Exploitability

The CVE description does not report a CVSS score, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. The lack of published exploitation metrics means the likelihood of real-world exploitation cannot be quantified, but the ability to run arbitrary code implies high potential impact. Based on the description, the likely attack vector is network traffic that can reach the router’s management or data plane pathways, though explicit details are missing.

Generated by OpenCVE AI on August 18, 2026 at 00:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Tenda W20E firmware to the latest version that includes a patch for CVE‑2026‑67967.
  • Disable any remote management interfaces (such as WAN‑side HTTP/HTTPS, SSH, or Telnet) if they are not required, to reduce the attack surface.
  • Monitor the device for abnormal activity and ensure it is isolated from critical internal networks until a secure patch is applied.

Generated by OpenCVE AI on August 18, 2026 at 00:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in Tenda W20E V16.01.0.6 Enables Arbitrary Code Execution
Weaknesses CWE-119

Mon, 17 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Tenda
Tenda w20e
Vendors & Products Tenda
Tenda w20e

Mon, 17 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description Buffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782) allows an attacker to execute arbitrary code. This is an incomplete fix for CVE-2025-44867 and CVE-2026-36819
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-17T20:43:04.557Z

Reserved: 2026-07-30T00:00:00.000Z

Link: CVE-2026-67967

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-17T21:16:47.840

Modified: 2026-08-17T21:16:47.840

Link: CVE-2026-67967

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T00:15:03Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer