Tenda W20E Stack-Based Buffer Overflow Vulnerability in Web Management Interface

Vulnerability

A stack-based buffer overflow vulnerability has been identified in the Tenda W20E router, specifically in version 15.11.0.6. The issue resides in the web management interface, within the 'modifyWifiFilterRules' function of the '/goform/modifyWifiFilterRules' endpoint. The vulnerability is triggered by sending an overly long string in the 'wifiFilterListRemark' parameter. This exploitation can be initiated remotely, and while it may cause a denial-of-service by crashing the web service, it could also lead to remote code execution.

Impact

Exploitation of this vulnerability can cause a denial-of-service by crashing the web service, and may also allow for remote code execution.

Reproduction

To reproduce this vulnerability, send a POST request to the '/goform/modifyWifiFilterRules' endpoint with a crafted 'wifiFilterListRemark' parameter containing an excessively long string. The vulnerability can be exploited after establishing a session and, if necessary, setting a cookie to simulate an authenticated user.

Added: Jun 8, 2026, 5:25 PM
Updated: Jun 8, 2026, 5:25 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
7.5
exploitability
7.0
remediation
0.0
relevance
9.4
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.