CVE-2026-4960

8.8

Tenda · AC6

Tenda AC6 version 15.03.05.16 contains a stack-based buffer overflow in the /goform/WizardHandle function, reachable via the WANT/WANS argument.

Executive summary

A stack-based buffer overflow in Tenda AC6 allows remote authenticated attackers to execute arbitrary code or cause a system crash.

Vulnerability

This vulnerability is a stack-based buffer overflow (CWE-121) triggered by manipulating the WANT/WANS argument in the /goform/WizardHandle function. The vulnerability is remotely exploitable by an authenticated user.

Business impact

The potential for stack-based buffer overflow allows an attacker to achieve remote code execution, which could lead to full device compromise. Given the CVSS score of 8.8, this vulnerability poses a high risk to network integrity, as compromised routers may be used to intercept traffic or facilitate lateral movement within the local network.

Remediation

Immediate Action: Since no specific patch version is currently identified, verify if the vendor has released a firmware update addressing this specific function and apply it immediately. If no update is available, restrict management access to the router to trusted IP addresses only.

Proactive Monitoring: Monitor device logs for unusual POST requests directed at the /goform/WizardHandle endpoint. Investigate any unexpected device reboots or performance degradation that may indicate exploitation attempts.

Compensating Controls: If the device supports it, disable the web management interface from the WAN side to prevent remote access by unauthorized actors. Ensure the router is placed behind a robust firewall that inspects administrative traffic.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists, attributed to the security researcher write-up linked in the vulnerability references.

Analyst recommendation

The presence of a publicly disclosed proof-of-concept significantly lowers the barrier for exploitation, making this a high-priority concern for administrators of Tenda AC6 hardware. It is essential to restrict administrative access and prioritize the application of any forthcoming vendor firmware updates to mitigate the threat of remote code execution.

More Tenda CVEs

Sources

Originally found and disclosed by wxhwxhwxh_mie (VulDB User), per the CVE Program record.