CVE-2026-24108: Buffer Overflow
An issue was discovered in Tenda W20E V4.0brV15.11.0.6. Attackers may exploit the vulnerability by controlling the value of nptr. When this value is passed into the getMibPrefix function and concatenated using sprintf without proper size validation, it could lead to a buffer overflow vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24108?
CVE-2026-24108 has been classified with a critical severity due to the potential for remote code execution via buffer overflow.
How do I fix CVE-2026-24108?
To fix CVE-2026-24108, update the Tenda W20E to the latest firmware version that addresses this vulnerability.
Who is affected by CVE-2026-24108?
CVE-2026-24108 affects users of the Tenda W20E with firmware version 15.11.0.6.
What are the potential impacts of exploiting CVE-2026-24108?
Exploitation of CVE-2026-24108 can lead to remote code execution, allowing attackers to gain control over the device.
Is there a workaround for CVE-2026-24108?
There are no specific workarounds for CVE-2026-24108 besides updating to a patched version of the firmware.