CVE-2026-6016

8.8

Tenda · AC9

A stack-based buffer overflow in the Tenda AC9 router allows remote attackers to trigger memory corruption via a crafted POST request to the WizardHandle endpoint.

Executive summary

A critical stack-based buffer overflow vulnerability in Tenda AC9 routers allows remote, authenticated attackers to execute arbitrary code or cause a system crash.

Vulnerability

The flaw exists in the decodePwd function within the /goform/WizardHandle file, which processes POST requests. An attacker with low-level privileges can trigger a stack-based buffer overflow by manipulating the WANS argument.

Business impact

This vulnerability poses a significant risk to network integrity and confidentiality, as successful exploitation could lead to full system compromise or persistent denial of service. With a CVSS score of 8.8, the impact is severe, potentially allowing an attacker to intercept traffic or gain administrative control over the network infrastructure.

Remediation

Immediate Action: Since a specific patch is not currently confirmed, users should restrict access to the web management interface to trusted internal segments and disable the WizardHandle functionality if possible.

Proactive Monitoring: Monitor network traffic for unusual POST requests directed at the /goform/WizardHandle endpoint and watch for unexpected router reboots or service instability.

Compensating Controls: Deploy a Web Application Firewall (WAF) or an intrusion detection system to filter and block malicious traffic containing abnormally long inputs in the WANS parameter.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the technical write-up provided by the researcher.

Analyst recommendation

Given the presence of a public proof-of-concept and the high CVSS severity, this vulnerability presents a credible risk to Tenda AC9 deployments. Administrators must prioritize isolating affected devices from external exposure and monitor vendor communication channels for the release of a firmware update to permanently remediate the buffer overflow.

More Tenda CVEs

Sources

Originally found and disclosed by wxhwxhwxh_mie (VulDB User), per the CVE Program record.