PT-2026-22601 · Tenda · Tenda W20E

Akuma-Qaq

·

Published

2026-03-02

·

Updated

2026-03-07

·

CVE-2026-24111

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Tenda W20E version 4.0br V15.11.0.6
Description An issue exists in Tenda W20E firmware where improper input validation can lead to a buffer overflow. Attackers can exploit this by manipulating the userInfo variable. Specifically, when the userInfo value is passed to the addAuthUser function and processed by the sscanf function without sufficient size validation, a buffer overflow can occur.
Recommendations Update to a newer version of Tenda W20E firmware that addresses this vulnerability.

Exploit

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2026-02501
CVE-2026-24111

Affected Products

Tenda W20E