What is CVE-2026-19823?
A stack-based buffer overflow vulnerability was discovered in the `formQOSRuleDel` function of `/goform/delQos` in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC, triggered by manipulating the `qosIndex` argument. This flaw allows remote exploitation, potentially leading to code execution or denial of service. Users should restrict remote management access until an official patch is released.
Azərbaycanca: Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC proqramında `/goform/delQos` faylındakı `formQOSRuleDel` funksiyasında `qosIndex` arqumentinin manipulyasiyası nəticəsində stack-based buffer overflow zəifliyi aşkarlanıb. Bu boşluq uzaqdan istismar edilərək cihazda kod icrasına və ya xidmət rəddinə səbəb ola bilər. İstehsalçı tərəfindən rəsmi yamaq buraxılana qədər cihazın uzaqdan idarəetmə funksiyalarının məhdudlaşdırılması tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119; shared vendor: Tenda
FAQ2
What remote impact can this vulnerability in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC cause?
This vulnerability can be exploited remotely, potentially leading to code execution or denial of service.
What mitigation is recommended until the vendor releases a patch?
Users should restrict remote management access until an official patch is released.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.