CVE-2026-19823: Tenda W20E QoS Rule Deletion delQos formQOSRuleDel stack-based overflow
Published Aug 14, 2026
·Updated
A security flaw has been discovered in Tenda W20E 15.11.0.6(10681546841)CNTDC. Impacted is the function formQOSRuleDel of the file /goform/delQos of the component QoS Rule Deletion. Performing a manipulation of the argument qosIndex results in stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.
Affected Software
1 affected component
Tenda W20E=15.11.0.6(1068_1546_841)_CN_TDC
Event History
Aug 14, 2026
CVE Published
via MITRE·12:15 PM
Data Sourced
via MITRE·12:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-19823?
CVE-2026-19823 has a high severity rating of 8.8.
2
How do I fix CVE-2026-19823?
To fix CVE-2026-19823, update your Tenda W20E firmware to the latest version.
3
What type of vulnerability is CVE-2026-19823?
CVE-2026-19823 is a stack-based buffer overflow vulnerability.
4
Which component is affected by CVE-2026-19823?
CVE-2026-19823 affects the QoS Rule Deletion function in Tenda W20E.
5
What is the impact of exploiting CVE-2026-19823?
Exploitation of CVE-2026-19823 can lead to remote code execution with high privileges.