Description
A security flaw has been discovered in Tenda W20E 15.11.0.61068_1546_841_CN_TDC. Impacted is the function formDelWebAuthWhiteUser. Performing a manipulation of the argument webAuthWhiteUserIndex results in stack-based buffer overflow. The attack can be initiated remotely.
Published: 2026-09-14
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Stack‑based buffer overflow exploitable remotely
Action: Patch
AI Analysis

Impact

A stack‑based buffer overflow exists in the formDelWebAuthWhiteUser function of the Tenda W20E firmware. Manipulating the webAuthWhiteUserIndex argument leads to uncontrolled stack writes that may trigger arbitrary code execution, a crash, or other unintended device behavior. The flaw can be triggered from a remote connection to the management interface, so local privileges are not required.

Affected Systems

The vulnerability is present in Tenda W20E routers running firmware release 15.11.0.61068_1546_841_CN_TDC. Administrators should verify that their devices are on this firmware version and apply any available updates.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity. The EPSS score indicates a very low but nonzero probability of exploitation (less than 1%). The flaw is not listed in the CISA KEV catalog. Because the attack vector is remote and does not require local access, the risk to systems that expose the affected management interface is significant.

Generated by OpenCVE AI on September 15, 2026 at 16:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the router firmware to a version that resolves stack‑based buffer overflows (CWE‑119 and CWE‑121).
  • If a firmware update is not yet available or cannot be applied, block remote access to the management interface by configuring firewall rules, VLAN segmentation, or disabling the exposed port or service from the public network.
  • Continuously monitor the router’s logs for unauthorized authentication attempts or other anomalous activity that could indicate exploitation of this flaw.

Generated by OpenCVE AI on September 15, 2026 at 16:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Tenda w20e
Vendors & Products Tenda w20e

Mon, 14 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in Tenda W20E 15.11.0.61068_1546_841_CN_TDC. Impacted is the function formDelWebAuthWhiteUser. Performing a manipulation of the argument webAuthWhiteUserIndex results in stack-based buffer overflow. The attack can be initiated remotely.
Title Tenda W20E formDelWebAuthWhiteUser stack-based overflow
First Time appeared Tenda
Tenda w20e Firmware
Weaknesses CWE-119
CWE-121
CPEs cpe:2.3:o:tenda:w20e_firmware:*:*:*:*:*:*:*:*
Vendors & Products Tenda
Tenda w20e Firmware
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Tenda W20e W20e Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T10:55:57.386Z

Reserved: 2026-09-13T05:01:50.679Z

Link: CVE-2026-90689

cve-icon Vulnrichment

Updated: 2026-09-14T10:55:37.695Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T07:17:24.700

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90689

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T16:15:15Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-121

    Stack-based Buffer Overflow