PT-2026-71979 · Tenda · W20E
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Tenda W20E version 15.11.0.6(1068 1546 841) CN TDC
Description
A stack-based buffer overflow occurs in the QoS Edit component when the
lstAdd() function in the '/goform/editQos' endpoint processes a manipulated qosListConnecttedNum argument. This issue allows for remote attacks.Recommendations
As a temporary workaround, restrict access to the '/goform/editQos' endpoint or avoid using the
qosListConnecttedNum argument until a fix is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Buffer Overflow
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
W20E