Stack-Based Buffer Overflow in Tenda W20E QoS Rule Deletion Function
CVE-2026-19823
Key Information:
Badges
What is CVE-2026-19823?
A security vulnerability has been identified in the Tenda W20E router that affects the QoS Rule Deletion feature. The issue resides within the formQOSRuleDel function located in the /goform/delQos file. An attacker can exploit this flaw by manipulating the qosIndex argument, leading to a stack-based buffer overflow. This vulnerability could be exploited remotely, making it a critical concern for users of the affected version. As the exploit has been released to the public, it emphasizes the importance of prompt remediation.
Affected Version(s)
W20E 15.11.0.6(1068_1546_841)_CN_TDC
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved