Tenda W20E Buffer Overflow Vulnerability in DHCP Rule Management

Vulnerability

A buffer overflow vulnerability has been identified in the Tenda W20E router, specifically in version V4.0br_V15.11.0.6. The issue arises in the DHCP rule management feature, where attackers can send excessively long data through the 'addDhcpRules' parameter. The 'addDhcpRule' function processes this data without proper size validation, leading to potential buffer overflows in the 'dhcpsIndex', 'dhcpsIP', and 'dhcpsMac' variables.

Impact

Exploitation of this vulnerability can lead to arbitrary code execution or causing the device to become unresponsive.

Added: Mar 2, 2026, 4:23 PM
Updated: Mar 2, 2026, 9:44 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
7.5
exploitability
7.8
remediation
0.0
relevance
3.4
threat
0.0
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.