Tenda W20E Buffer Overflow Vulnerability in goform/formDelWewifiPic

Vulnerability

A buffer overflow vulnerability has been identified in the Tenda W20E router, specifically in version V4.0br_V15.11.0.6. The issue arises in the goform/formDelWewifiPic component, where attackers can manipulate the picName parameter. This parameter is processed using sprintf without proper size validation, creating the potential for a buffer overflow exploit.

Impact

Exploitation of this vulnerability leads to a buffer overflow, which can commonly result in arbitrary code execution or causing the device to crash.

Reproduction

To reproduce this vulnerability, send a POST request to the /goform/formDelWewifiPic endpoint. Include a picName parameter with a value that exceeds the buffer size limit. The request should be made with a Content-Type of application/x-www-form-urlencoded.

Added: Mar 2, 2026, 3:23 PM
Updated: Mar 2, 2026, 9:58 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
1.3
exploitability
9.1
remediation
0.0
relevance
3.4
threat
6.4
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.