What is CVE-2026-19822?
A stack-based buffer overflow vulnerability was identified in the QoS Edit component of Tenda W20E routers, specifically in the `lstAdd` function of `/goform/editQos`. The issue is triggered via the `qosListConnecttedNum` argument, allowing remote exploitation. This affects version 15.11.0.6(1068_1546_841)_CN_TDC.
Azərbaycanca: Tenda W20E router qurğusunun QoS redaktə komponentində stack-based buffer overflow zəifliyi aşkarlanıb. Bu zəiflik `/goform/editQos` funksiyasındakı `qosListConnecttedNum` arqumenti vasitəsilə uzaqdan hücuma imkan yaradır. Zəiflikdən təsirlənən versiya 15.11.0.6(1068_1546_841)_CN_TDC-dir.
Related CVEs
link basis: same weakness class CWE-119; shared vendor: Tenda
FAQ2
Which function in Tenda W20E is affected by CVE-2026-19822?
The vulnerability lies in the `lstAdd` component of the `/goform/editQos` function.
Which argument is manipulated for remote exploitation of CVE-2026-19822?
The remote attack is carried out via the `qosListConnecttedNum` argument.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.