CVE-2026-6016: Tenda AC9 POST Request WizardHandle decodePwd stack-based overflow
A vulnerability was found in Tenda AC9 15.03.02.13. The affected element is the function decodePwd of the file /goform/WizardHandle of the component POST Request Handler. Performing a manipulation of the argument WANS results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6016?
CVE-2026-6016 has a high severity due to its potential for stack-based overflow, which can lead to remote code execution.
How do I fix CVE-2026-6016?
To fix CVE-2026-6016, update the Tenda AC9 firmware to the latest stable version released after 15.03.02.13.
What are the potential impacts of CVE-2026-6016?
The potential impacts of CVE-2026-6016 include unauthorized command execution and system instability.
Is CVE-2026-6016 exploitable remotely?
Yes, CVE-2026-6016 is exploitable remotely through the affected POST Request Handler in the device.
What devices are affected by CVE-2026-6016?
CVE-2026-6016 affects Tenda AC9 devices running firmware version 15.03.02.13.