CVE-2026-24112: Buffer Overflow
An issue was discovered in Tenda W20E V4.0brV15.11.0.6. Attackers may exploit the vulnerability by specifying the value of userInfo. When userInfo is passed into the addWewifiWhiteUser function and processed by sscanf without size validation, it could lead to a buffer overflow vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24112?
CVE-2026-24112 is considered a high severity vulnerability due to the risk of buffer overflow attacks.
How do I fix CVE-2026-24112?
To fix CVE-2026-24112, upgrade the Tenda W20E firmware to version 15.11.0.7 or later, which addresses the vulnerability.
Which versions of Tenda W20E are affected by CVE-2026-24112?
CVE-2026-24112 affects Tenda W20E firmware version 15.11.0.6.
Can CVE-2026-24112 lead to unauthorized access?
Yes, CVE-2026-24112 can potentially lead to unauthorized access through buffer overflow exploits.
What should users do while waiting for a patch for CVE-2026-24112?
Users should restrict access to their devices and monitor for any suspicious activity until a patch for CVE-2026-24112 is applied.