CVE-2026-24109: Buffer Overflow
An issue was discovered in Tenda W20E V4.0brV15.11.0.6. Attackers may exploit the vulnerability by controlling the value of picName. When this value is used in sprintf without validating variable sizes, it could lead to a buffer overflow vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24109?
CVE-2026-24109 is a critical vulnerability due to the potential for buffer overflow, which can lead to remote code execution.
How do I fix CVE-2026-24109?
To fix CVE-2026-24109, users should update the Tenda W20E firmware to the latest version that addresses this vulnerability.
Who is affected by CVE-2026-24109?
CVE-2026-24109 affects users of Tenda W20E with firmware version 15.11.0.6.
What does CVE-2026-24109 allow attackers to do?
CVE-2026-24109 allows attackers to exploit a buffer overflow through uncontrolled input, potentially allowing code execution.
When was CVE-2026-24109 discovered?
CVE-2026-24109 was discovered recently and highlights an issue in the Tenda W20E firmware.