CVE-2026-19822: Tenda W20E QoS Edit editQos lstAdd stack-based overflow
A vulnerability was identified in Tenda W20E 15.11.0.6(10681546841)CNTDC. This issue affects the function lstAdd of the file /goform/editQos of the component QoS Edit. Such manipulation of the argument qosListConnecttedNum leads to stack-based buffer overflow. The attack may be launched remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19822?
The severity of CVE-2026-19822 is rated as high with a score of 8.8.
How do I fix CVE-2026-19822?
To fix CVE-2026-19822, update Tenda W20E to the latest firmware version that addresses this vulnerability.
What type of vulnerability is CVE-2026-19822?
CVE-2026-19822 is classified as a buffer overflow vulnerability.
Can CVE-2026-19822 be exploited remotely?
Yes, CVE-2026-19822 can be exploited remotely, allowing an attacker to manipulate the qosListConnecttedNum.
What component is affected by CVE-2026-19822?
CVE-2026-19822 affects the QoS Edit function lstAdd in the Tenda W20E.