Buffer Overflow in Tenda W15E from Shenzhen Tenda Technology Co., Ltd
CVE-2026-36806

7.5HIGH

What is CVE-2026-36806?

The Tenda W15E router version 15.11.0.10 is susceptible to a buffer overflow vulnerability due to improper handling of the webAuthUserPwd parameter in the formModifyWebAuthUser function. This flaw enables attackers to exploit the vulnerability by sending specially crafted HTTP requests, which may lead to a Denial of Service (DoS) condition, thereby disrupting the availability of the device.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.