Stack-Based Buffer Overflow in Tenda W20E Router
CVE-2026-90688

7.1HIGH

Key Information:

Vendor

Tenda

Status
Vendor
CVE Published:
14 September 2026

What is CVE-2026-90688?

A noteworthy vulnerability exists in the Tenda W20E router where improper handling of the formIPMacBindAdd function within the HTTP Handler can lead to a stack-based buffer overflow. By exploiting this vulnerability, remote attackers may manipulate the IPMacBindRule argument, potentially gaining unauthorized access and control over affected devices. It highlights the need for vigilant network security practices and timely patches to address such critical flaws.

Affected Version(s)

W20E 15.11.0.61068_1546_841_CN_TDC

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

AmaIIl (VulDB User)
.