Description
A vulnerability was identified in Tenda W20E 15.11.0.61068_1546_841_CN_TDC. This issue affects the function formIPMacBindAdd of the component HTTP Handler. Such manipulation of the argument IPMacBindRule leads to stack-based buffer overflow. It is possible to launch the attack remotely.
Published: 2026-09-14
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote stack-based buffer overflow
Action: Immediate Patch
AI Analysis

Impact

A stack‑based buffer overflow exists in the formIPMacBindAdd function of the HTTP Handler in Tenda W20E firmware version 15.11.0.61068_1546_841_CN_TDC. The flaw is triggered by manipulating the IPMacBindRule argument with a maliciously crafted value. Attackers can send a POST request over HTTP to trigger the overflow, potentially compromising the device’s integrity and creating opportunities for further exploitation.

Affected Systems

The vulnerability affects the Tenda W20E router running firmware 15.11.0.61068_1546_841_CN_TDC. No other firmware versions or products are listed as affected.

Risk and Exploitability

The CVSS base score is 7.1, indicating high severity, and the EPSS score is less than 1%, suggesting that attacks are infrequent at present. The vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the stack overflow remotely via the HTTP formIPMacBindAdd endpoint, which could lead to integrity violations or potential code execution, although the CVE description does not confirm arbitrary code execution.

Generated by OpenCVE AI on September 15, 2026 at 17:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the router to the latest firmware that addresses the formIPMacBindAdd overflow.
  • If no firmware update is available, block HTTP access to the configuration interface from untrusted networks or restrict it to a trusted management subnet.
  • Monitor the device for abnormal POST requests to the formIPMacBindAdd endpoint and set alerts for suspicious activity.

Generated by OpenCVE AI on September 15, 2026 at 17:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
First Time appeared Tenda w20e
Vendors & Products Tenda w20e

Mon, 14 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in Tenda W20E 15.11.0.61068_1546_841_CN_TDC. This issue affects the function formIPMacBindAdd of the component HTTP Handler. Such manipulation of the argument IPMacBindRule leads to stack-based buffer overflow. It is possible to launch the attack remotely.
Title Tenda W20E HTTP formIPMacBindAdd stack-based overflow
First Time appeared Tenda
Tenda w20e Firmware
Weaknesses CWE-119
CWE-121
CPEs cpe:2.3:o:tenda:w20e_firmware:*:*:*:*:*:*:*:*
Vendors & Products Tenda
Tenda w20e Firmware
References
Metrics cvssV2_0

{'score': 6.8, 'vector': 'AV:N/AC:L/Au:S/C:N/I:N/A:C/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Tenda W20e W20e Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T15:57:34.857Z

Reserved: 2026-09-13T05:01:47.157Z

Link: CVE-2026-90688

cve-icon Vulnrichment

Updated: 2026-09-15T15:57:08.404Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T07:17:24.513

Modified: 2026-09-15T16:17:39.990

Link: CVE-2026-90688

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:15:14Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-121

    Stack-based Buffer Overflow