Stack-Based Buffer Overflow in Tenda W6-S by Tenda
CVE-2026-67822

9.8CRITICAL

Key Information:

Vendor

Tenda

Vendor
CVE Published:
31 July 2026

What is CVE-2026-67822?

The Tenda W6-S device version 1.0.0.4(510) is susceptible to a stack-based buffer overflow due to improper handling of user-controlled input in the '/goform/wifiSSIDset' endpoint. Specifically, the function 'formwrlSSIDset' misuses the 'sprintf' function to copy parameters without imposing length restrictions. This flaw could lead to overwriting memory, potentially allowing for execution of arbitrary code and compromising the security integrity of the affected device.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.