CVE-2026-6015

8.8

Tenda · AC9

A stack-based buffer overflow in the Tenda AC9 router allows remote attackers to trigger memory corruption via a crafted PPPOEPassword argument in the formQuickIndex function.

Executive summary

A critical remote code execution vulnerability in Tenda AC9 routers allows attackers to trigger a stack-based buffer overflow via an unauthenticated or low-privilege network request.

Vulnerability

This vulnerability consists of a stack-based buffer overflow within the formQuickIndex function of the /goform/QuickIndex endpoint. By sending a crafted POST request containing a malicious PPPOEPassword argument, an attacker can corrupt memory on the device.

Business impact

The exploitation of this vulnerability can lead to a complete compromise of the affected router, resulting in unauthorized network access, data interception, or the potential for further lateral movement within the local network. Given the CVSS score of 8.8, this flaw represents a high risk to organizational security, particularly for remote or branch office environments relying on this hardware.

Remediation

Immediate Action: Since a vendor-provided patch is currently unknown, users should restrict administrative access to the router interface and ensure it is not exposed to the public internet.

Proactive Monitoring: Monitor network traffic for anomalous POST requests directed at the /goform/QuickIndex endpoint, which may indicate attempted exploitation.

Compensating Controls: Implement firewall rules to block unsolicited inbound traffic to the management interface of the Tenda AC9 device.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the research write-up referenced in the vulnerability disclosure.

Analyst recommendation

Organizations utilizing Tenda AC9 hardware must treat this vulnerability with high urgency due to the availability of public proof-of-concept code. Administrators should immediately isolate the device from external network exposure and monitor the vendor's official support channels for the release of a firmware update to address this buffer overflow.

More Tenda CVEs

Sources

Originally found and disclosed by wxhwxhwxh_mie (VulDB User), per the CVE Program record.