Impact
A stack‑based buffer overflow exists in the formDelWebAuthWhiteUser function of the Tenda W20E firmware. Manipulating the webAuthWhiteUserIndex argument leads to uncontrolled stack writes that may trigger arbitrary code execution, a crash, or other unintended device behavior. The flaw can be triggered from a remote connection to the management interface, so local privileges are not required.
Affected Systems
The vulnerability is present in Tenda W20E routers running firmware release 15.11.0.61068_1546_841_CN_TDC. Administrators should verify that their devices are on this firmware version and apply any available updates.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity. The EPSS score indicates a very low but nonzero probability of exploitation (less than 1%). The flaw is not listed in the CISA KEV catalog. Because the attack vector is remote and does not require local access, the risk to systems that expose the affected management interface is significant.
OpenCVE Enrichment