Stack-Based Buffer Overflow in Tenda W6-S by Tenda
CVE-2026-67822
9.8CRITICAL
What is CVE-2026-67822?
The Tenda W6-S device version 1.0.0.4(510) is susceptible to a stack-based buffer overflow due to improper handling of user-controlled input in the '/goform/wifiSSIDset' endpoint. Specifically, the function 'formwrlSSIDset' misuses the 'sprintf' function to copy parameters without imposing length restrictions. This flaw could lead to overwriting memory, potentially allowing for execution of arbitrary code and compromising the security integrity of the affected device.