CVE-2026-6015
8.8Tenda · AC9
A stack-based buffer overflow in the Tenda AC9 router allows remote attackers to trigger memory corruption via a crafted PPPOEPassword argument in the formQuickIndex function.
Executive summary
A critical remote code execution vulnerability in Tenda AC9 routers allows attackers to trigger a stack-based buffer overflow via an unauthenticated or low-privilege network request.
Vulnerability
This vulnerability consists of a stack-based buffer overflow within the formQuickIndex function of the /goform/QuickIndex endpoint. By sending a crafted POST request containing a malicious PPPOEPassword argument, an attacker can corrupt memory on the device.
Business impact
The exploitation of this vulnerability can lead to a complete compromise of the affected router, resulting in unauthorized network access, data interception, or the potential for further lateral movement within the local network. Given the CVSS score of 8.8, this flaw represents a high risk to organizational security, particularly for remote or branch office environments relying on this hardware.
Remediation
Immediate Action: Since a vendor-provided patch is currently unknown, users should restrict administrative access to the router interface and ensure it is not exposed to the public internet.
Proactive Monitoring: Monitor network traffic for anomalous POST requests directed at the /goform/QuickIndex endpoint, which may indicate attempted exploitation.
Compensating Controls: Implement firewall rules to block unsolicited inbound traffic to the management interface of the Tenda AC9 device.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the research write-up referenced in the vulnerability disclosure.
Analyst recommendation
Organizations utilizing Tenda AC9 hardware must treat this vulnerability with high urgency due to the availability of public proof-of-concept code. Administrators should immediately isolate the device from external network exposure and monitor the vendor's official support channels for the release of a firmware update to address this buffer overflow.
More Tenda CVEs
Sources
Originally found and disclosed by wxhwxhwxh_mie (VulDB User), per the CVE Program record.
- VDB-356571 | Tenda AC9 POST Request QuickIndex formQuickIndex stack-based overflow Vulnerability database entry
- VDB-356571 | CTI Indicators (IOB, IOC, IOA)
- Submit #791828 | Tenda AC9 AC9 V1.0 V15.03.02.13 Buffer Overflow Third-party advisory
- Exploit / PoC
- tenda.com.cn