CVE-2026-6015: Tenda AC9 POST Request QuickIndex formQuickIndex stack-based overflow
A vulnerability has been found in Tenda AC9 15.03.02.13. Impacted is the function formQuickIndex of the file /goform/QuickIndex of the component POST Request Handler. Such manipulation of the argument PPPOEPassword leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6015?
CVE-2026-6015 is considered a high severity vulnerability due to its potential for stack-based overflow in Tenda AC9 devices.
How do I fix CVE-2026-6015?
To fix CVE-2026-6015, users should update their Tenda AC9 firmware to the latest version that addresses this vulnerability.
What type of vulnerability is CVE-2026-6015?
CVE-2026-6015 is categorized as a stack-based buffer overflow vulnerability.
Which devices are affected by CVE-2026-6015?
CVE-2026-6015 affects Tenda AC9 devices running firmware version 15.03.02.13.
What components are involved in CVE-2026-6015?
CVE-2026-6015 involves the POST Request Handler specifically in the function formQuickIndex.