What is CVE-2026-19824?
A stack-based buffer overflow vulnerability has been found in the `ipMacBindListStore` function in `/goform/addIpMacBind` of Tenda W20E router firmware version 15.11.0.6(1068_1546_841)_CN_TDC. Remote exploitation is possible by manipulating the `IPMacBindRule` argument, potentially allowing control over the device. Immediate firmware update or network isolation is required to mitigate the risk.
Azərbaycanca: Tenda W20E routerinin 15.11.0.6(1068_1546_841)_CN_TDC versiyasında `/goform/addIpMacBind` faylındakı `ipMacBindListStore` funksiyasında stack-based buffer overflow zəifliyi aşkar edilib. Bu, uzaqdan icra oluna bilən hücumdur — `IPMacBindRule` arqumentinə xüsusi hazırlanmış verilən ötürməklə cihazın nəzarətini ələ keçirməyə imkan yaradır. Routeri bu zəifliyi hədəfləyən şəbəkə trafikindən qorumaq üçün dərhal firmware yeniləməsi tətbiq edilməli və ya cihaz internetə açıq qoyulmamalıdır.
Related CVEs
link basis: same weakness class CWE-119; shared vendor: Tenda
FAQ2
Which version of Tenda W20E router is affected by CVE-2026-19824?
Firmware version 15.11.0.6(1068_1546_841)_CN_TDC.
Which argument is manipulated to exploit CVE-2026-19824 remotely?
The `IPMacBindRule` argument.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.