Stack Overflow Vulnerability in Tenda G0 by Shenzhen Tenda Technology Co., Ltd
CVE-2026-36798

6.5MEDIUM

What is CVE-2026-36798?

The Tenda G0 firmware version 15.11.0.5 is prone to multiple stack overflow vulnerabilities stemming from improper handling of parameters in the formSetDebugCfgr function. Specifically, parameters such as enable, level, and module can be manipulated through crafted HTTP requests, potentially leading to a Denial of Service (DoS). This can disrupt normal operation and accessibility of the affected device, posing significant risks to network integrity.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.