top of page
perceptive_background_267k.jpg

Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to co…

Published:

30 juli 2026 om 22:00:00

Alert date:

31 juli 2026 om 20:02:34

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT, Network Infrastructure

Tenda W6-S firmware version 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The vulnerable function formwrlSSIDset uses the unsafe sprintf function to copy user-controlled HTTP parameters 'GO' and 'index' into a fixed 64-byte stack buffer. No length validation or restriction is applied to the input, allowing an attacker to overflow the stack buffer. This could potentially lead to remote code execution or denial of service on the affected device. The vulnerability affects the Tenda W6-S wireless router product line. A proof-of-concept writeup has been published on GitHub demonstrating the overflow condition. IoT/router vulnerabilities of this class are commonly targeted by botnet campaigns and threat actors seeking persistent network footholds.

Technical details

Mitigation steps:

Affected products:

Tenda W6-S 1.0.0.4(510)

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page