CVE-2026-1420
8.8Tenda · AC23
A buffer overflow vulnerability exists in the Tenda AC23 router, specifically within the /goform/WifiExtraSet endpoint, allowing for potential remote code execution via manipulation of the wpapsk_crypto argument.
Executive summary
A critical buffer overflow vulnerability in Tenda AC23 routers allows authenticated remote attackers to execute arbitrary code, posing a significant risk to network integrity.
Vulnerability
This flaw is a buffer overflow (CWE-120) triggered by providing malicious input to the wpapsk_crypto argument in the /goform/WifiExtraSet function. The vulnerability is exploitable by an authenticated user with low-level privileges.
Business impact
The exploitation of this buffer overflow can lead to full system compromise, allowing an attacker to gain unauthorized control over the networking device. Given the CVSS score of 8.8, this vulnerability presents a high risk of lateral movement within the network, potential interception of sensitive traffic, or complete loss of router availability, which could result in significant operational disruption.
Remediation
Immediate Action: Contact Tenda support or monitor the official Tenda website for firmware updates addressing this buffer overflow, as no official patch is currently listed.
Proactive Monitoring: Review device access logs for suspicious activity directed at the /goform/WifiExtraSet endpoint and monitor for unusual spikes in memory usage or unexpected service restarts.
Compensating Controls: Restrict access to the router administrative interface to trusted management IP addresses only, and employ network segmentation to minimize the impact of a potential device compromise.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists as documented in the researcher's technical write-up on GitHub.
Analyst recommendation
The presence of a publicly available proof-of-concept for this memory corruption vulnerability necessitates immediate attention. Administrators should prioritize restricting administrative access to the affected Tenda AC23 devices and verify if a firmware update has been released by the vendor. Failure to mitigate this risk could grant an attacker persistent control over the network gateway.
More Tenda CVEs all →
History
- Disclosed CVE record published
- Published in the daily brief high section
- Published in the daily brief high section
- Analyst report written
Sources
Originally found and disclosed by xuanyu (VulDB User), per the CVE Program record.
- VDB-342836 | Tenda AC23 WifiExtraSet buffer overflow Vulnerability database entry
- VDB-342836 | CTI Indicators (IOB, IOC, IOA)
- Submit #736559 | Tenda AC23 V16.03.07.52 Buffer Overflow Third-party advisory
- Exploit / PoC
- Exploit / PoC
- tenda.com.cn