Tenda W20E是中国腾达(Tenda)公司的一款路由器。 Tenda W20E 15.11.0.6版本存在缓冲区错误漏洞,该漏洞源于文件/goform/setPortMirror中函数formSetPortMirror对参数portMirrorMirroredPorts的操作,可能导致栈缓冲区溢出。攻击者可远程发起攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-11499 | 9.8 CRITICAL | Tenda HG7/HG9/HG10 formDOMAINBLK stack-based overflow |
| CVE-2026-11498 | 8.8 HIGH | Tenda HG7/HG9/HG10 Web Management voip_other_set asp_voip_OtherSet stack-based overflow |
| CVE-2026-11503 | 8.8 HIGH | Tenda CX12L Wi-Fi Configuration Endpoint fast_setting_wifi_set form_fast_setting_wifi_set |
| CVE-2026-11504 | 8.8 HIGH | Tenda CX12L Wi-Fi Schedule Configuration Endpoint openSchedWifi setSchedWifi stack-based o |
| CVE-2026-11523 | 8.8 HIGH | Tenda W20E Web Management PortalAuth formPortalAuth stack-based overflow |
| CVE-2026-11524 | 8.8 HIGH | Tenda W20E Web Management modifyWifiFilterRules stack-based overflow |
| CVE-2026-11528 | 8.8 HIGH | Tenda AC18 Web Management getRebootStatus sub_45304 stack-based overflow |
| CVE-2026-11553 | 8.8 HIGH | Tenda HG7/HG9/HG10 formPPPEdit stack-based overflow |
| CVE-2026-11556 | 8.8 HIGH | Tenda F451 Web Management WriteFacMac formWriteFacMac os command injection |
| CVE-2026-11557 | 8.8 HIGH | Tenda F451 Web Management Natlimit fromNatlimit stack-based overflow |
| CVE-2026-11493 | 5.0 MEDIUM | Tenda AC15 Samba smb.conf weak password |
No comments yet