{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3atendaw20e/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:tenda:w20e:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-90689"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["W20E (15.11.0.61068_1546_841_CN_TDC)"],"_cs_severities":["high"],"_cs_tags":["cve-2026-90689","network-security","buffer-overflow"],"_cs_type":"advisory","_cs_vendors":["Tenda"],"content_html":"\u003cp\u003eA critical security vulnerability has been identified in Tenda W20E firmware version 15.11.0.61068_1546_841_CN_TDC. The flaw resides within the formDelWebAuthWhiteUser function, which processes the webAuthWhiteUserIndex argument without sufficient bounds checking. This oversight introduces a stack-based buffer overflow condition. Because the vulnerable function is reachable via remote HTTP requests, an unauthenticated attacker can exploit this flaw to crash the device, resulting in a denial of service, or potentially achieve remote code execution (RCE) by overwriting stack memory. This vulnerability poses a significant risk to network infrastructure, as the Tenda W20E is typically deployed as a gateway or router. Organizations using this device should restrict access to the web management interface to trusted IP ranges and monitor for unusual traffic patterns targeted at administrative URI paths.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker performs reconnaissance to identify Tenda W20E devices exposed to the internet.\u003c/li\u003e\n\u003cli\u003eThe attacker identifies the target URI or endpoint associated with the web authentication white user management functionality.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious HTTP request containing a specially crafted value for the webAuthWhiteUserIndex parameter.\u003c/li\u003e\n\u003cli\u003eThe request is transmitted to the device's web management interface.\u003c/li\u003e\n\u003cli\u003eThe device's formDelWebAuthWhiteUser function parses the malicious input.\u003c/li\u003e\n\u003cli\u003eThe lack of bounds checking results in a memory corruption event on the device stack.\u003c/li\u003e\n\u003cli\u003eDepending on the payload, the device either crashes (Denial of Service) or redirects the instruction pointer to attacker-controlled shellcode (Remote Code Execution).\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-90689 allows an unauthenticated remote attacker to compromise the integrity and availability of Tenda W20E hardware. If used for code execution, the attacker could gain persistent control over the network gateway, enabling traffic interception, lateral movement, or further exploitation of connected internal systems.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eRestrict access to the Tenda W20E web management interface to known, trusted administrative IP addresses via firewall rules to block remote exploitation attempts.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for anomalous POST requests to URI endpoints associated with white user management containing abnormally long or suspicious string patterns in the webAuthWhiteUserIndex parameter.\u003c/li\u003e\n\u003cli\u003eEngage Tenda support or check for firmware updates addressing CVE-2026-90689; apply all relevant patches immediately upon availability.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-14T07:31:09Z","date_published":"2026-09-14T07:31:09Z","id":"https://feed.craftedsignal.io/briefs/2026-09-tenda-w20e-overflow/","summary":"A stack-based buffer overflow in the Tenda W20E formDelWebAuthWhiteUser function allows remote unauthenticated attackers to execute arbitrary code or cause a denial of service via manipulation of the webAuthWhiteUserIndex argument.","title":"Remote Stack-Based Buffer Overflow in Tenda W20E","url":"https://feed.craftedsignal.io/briefs/2026-09-tenda-w20e-overflow/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:tenda:w20e:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}