{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-19822/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-19822"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["W20E (15.11.0.6(1068_1546_841)_CN_TDC)"],"_cs_severities":["high"],"_cs_tags":["cve-2026-19822","vulnerability","remote-code-execution","cve-2026-19823","buffer-overflow","rce","network-infrastructure"],"_cs_type":"advisory","_cs_vendors":["Tenda"],"content_html":"\u003cp\u003eA stack-based buffer overflow vulnerability has been identified in Tenda W20E firmware version 15.11.0.6(1068_1546_841)_CN_TDC. The flaw resides within the QoS Edit component, specifically in the 'lstAdd' function called by the '/goform/editQos' endpoint. An attacker can trigger this condition by supplying a malicious payload to the 'qosListConnecttedNum' argument. The vulnerability, tracked as CVE-2026-19822, is exploitable remotely and proof-of-concept exploit code is publicly available. Given the potential for remote code execution, this represents a significant security risk for the impacted network gateway hardware.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs network reconnaissance to identify Tenda W20E devices exposed to the internet.\u003c/li\u003e\n\u003cli\u003eAttacker establishes an authenticated session with the target device.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP POST request targeting the /goform/editQos endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker inserts a specially crafted, oversized value into the qosListConnecttedNum parameter.\u003c/li\u003e\n\u003cli\u003eThe application passes the input to the vulnerable lstAdd function without proper bounds checking.\u003c/li\u003e\n\u003cli\u003eThe excessive data overflows the allocated buffer on the stack.\u003c/li\u003e\n\u003cli\u003eThe attacker overwrites return addresses or other critical stack data to hijack the control flow.\u003c/li\u003e\n\u003cli\u003eExecution of arbitrary code or denial of service is achieved on the affected device.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows for remote code execution on the Tenda W20E router. Given the position of these devices as network gateways, an attacker gaining code execution could facilitate lateral movement into the protected network, intercept traffic, or perform man-in-the-middle attacks. As of the time of reporting, the vulnerability is public and exploit material is accessible, increasing the likelihood of opportunistic exploitation against vulnerable firmware versions.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security operations and IT teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eCheck internal inventory for Tenda W20E devices running the affected firmware version 15.11.0.6(1068_1546_841)_CN_TDC.\u003c/li\u003e\n\u003cli\u003eApply the latest security patches provided by Tenda if available for this model.\u003c/li\u003e\n\u003cli\u003eRestrict access to the device web administration interface (/goform/editQos) to trusted management subnets only.\u003c/li\u003e\n\u003cli\u003eDeploy web application firewall (WAF) or intrusion detection system (IDS) rules to inspect and block HTTP requests containing abnormally long strings in the qosListConnecttedNum argument.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-14T14:13:09Z","date_published":"2026-08-14T14:11:56Z","id":"https://feed.craftedsignal.io/briefs/2026-08-tenda-buffer-overflow/","summary":"A stack-based buffer overflow vulnerability in Tenda W20E firmware allows authenticated remote attackers to achieve potential code execution via the QoS Edit component.","title":"Remote Stack-Based Buffer Overflow in Tenda W20E","url":"https://feed.craftedsignal.io/briefs/2026-08-tenda-buffer-overflow/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-19822","version":"https://jsonfeed.org/version/1.1"}