CVE-2026-11522: Tenda W20E setPortMirror formSetPortMirror stack-based overflow
A vulnerability was detected in Tenda W20E 15.11.0.6. This vulnerability affects the function formSetPortMirror of the file /goform/setPortMirror. Performing a manipulation of the argument portMirrorMirroredPorts results in stack-based buffer overflow. The attack can be initiated remotely. The exploit is now public and may be used.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable port mirroring on the Tenda W20E device or avoid using the setPortMirror form so the portMirrorMirroredPorts argument is not submitted.
Tenda W20E (formSetPortMirror) portMirrorMirroredPorts / port mirroring = disabled - Compensating control
Restrict access to the device management interface and the /goform/setPortMirror endpoint: disable remote/WAN management, limit management access to trusted IP addresses, and apply firewall/network segmentation rules to block HTTP POSTs to /goform/setPortMirror from untrusted networks.
- Operational
Monitor Tenda vendor advisories and apply any official firmware update or patch for the W20E that addresses this vulnerability as soon as it is published. If exploitation is suspected, isolate the device and follow incident response procedures.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11522?
The severity of CVE-2026-11522 is rated high with a score of 8.8.
How do I fix CVE-2026-11522?
Fixing CVE-2026-11522 involves updating the Tenda W20E firmware to the latest version provided by the vendor.
What type of attack can exploit CVE-2026-11522?
CVE-2026-11522 can be exploited through a remote attack that manipulates the portMirrorMirroredPorts argument.
What are the potential impacts of CVE-2026-11522?
The potential impacts of CVE-2026-11522 include unauthorized access and potential control over the Tenda W20E device due to stack-based buffer overflow.
Which software is affected by CVE-2026-11522?
CVE-2026-11522 affects the Tenda W20E router running firmware version 15.11.0.6.