CVE-2026-4961
8.8Tenda · AC6
A stack-based buffer overflow in the Tenda AC6 router allows remote attackers to trigger memory corruption via the PPPOEPassword argument in the formQuickIndex function.
Executive summary
A remote stack-based buffer overflow vulnerability in Tenda AC6 routers poses a critical risk of system compromise due to the availability of proof-of-concept exploit material.
Vulnerability
The vulnerability exists in the formQuickIndex function within the /goform/QuickIndex component, where improper handling of the PPPOEPassword argument leads to a stack-based buffer overflow. This flaw is remotely exploitable by an authenticated user, leading to potential memory corruption.
Business impact
The exploitation of this buffer overflow can lead to complete system compromise, including unauthorized execution of arbitrary code, denial of service, or total loss of router control. With a CVSS score of 8.8, this vulnerability represents a high severity risk that could facilitate unauthorized network access and compromise of internal traffic, threatening the confidentiality and integrity of the entire connected infrastructure.
Remediation
Immediate Action: Contact the vendor immediately to obtain firmware updates, as no official patch version is currently identified. If no patch is available, isolate the device from external network exposure until a secure version is released.
Proactive Monitoring: Monitor device access logs for unusual POST requests directed at the /goform/QuickIndex endpoint, particularly those containing oversized or unexpected strings in the PPPOEPassword field.
Compensating Controls: Deploy a network-level Web Application Firewall or intrusion prevention system to filter and block malicious traffic targeting the router administration interface.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists as documented in the technical write-up referenced by the CVE record.
Analyst recommendation
Given the high severity score and the existence of public proof-of-concept material, administrators should prioritize the mitigation of this vulnerability. Immediate steps should be taken to restrict access to the management interface of the affected Tenda AC6 devices and to monitor for any signs of exploitation attempts until a vendor-supplied firmware update is applied.
More Tenda CVEs
Sources
Originally found and disclosed by wxhwxhwxh_mie (VulDB User), per the CVE Program record.
- VDB-353838 | Tenda AC6 POST Request QuickIndex formQuickIndex stack-based overflow Vulnerability database entry
- VDB-353838 | CTI Indicators (IOB, IOC, IOA)
- Submit #777617 | Tenda AC6 AC6 V1.0 V15.03.05.16 Buffer Overflow Third-party advisory
- Exploit / PoC
- tenda.com.cn