CVE-2026-90689: Tenda W20E formDelWebAuthWhiteUser stack-based overflow
Published Sep 14, 2026
·Updated
A security flaw has been discovered in Tenda W20E 15.11.0.610681546841CNTDC. Impacted is the function formDelWebAuthWhiteUser. Performing a manipulation of the argument webAuthWhiteUserIndex results in stack-based buffer overflow. The attack can be initiated remotely.
Affected Software
1 affected component
Tenda W20E=15.11.0.61068_1546_841_CN_TDC
Event History
Sep 14, 2026
CVE Published
via MITRE·06:15 AM
Data Sourced
via MITRE·06:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The attack can be initiated remotely and has low attack complexity, but it requires low-level privileges. No user interaction is required.
2
Which product version is identified as affected?
The affected version identified is Tenda W20E 15.11.0.61068_1546_841_CN_TDC.
3
What security impact could successful exploitation have?
The supplied severity vector rates confidentiality, integrity, and availability impact as high. The vulnerability is a stack-based buffer overflow involving the webAuthWhiteUserIndex argument.