CVE-2026-67822 Details
Description
Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' parameters into a 64-byte stack buffer without length restriction, leading to stack overflow.
A stack-based buffer overflow vulnerability has been identified in the Tenda W6-S router, specifically in firmware version 1.0.0.4(510). The issue arises in the web server component, within the 'formwrlSSIDset' function of the '/goform/wifiSSIDset' endpoint. The vulnerability allows user-controlled 'GO' and 'index' parameters to be copied into a 64-byte stack buffer using 'sprintf', without any length validation. This lack of input sanitization enables attackers to overflow the buffer, potentially leading to a crash of the 'httpd' process and, in some cases, arbitrary code execution.
Users are advised to update to a version that addresses this vulnerability. Tenda W6-S firmware version 1.0.0.4(510) is vulnerable, and users should check the Tenda website or contact Tenda support for information on the latest firmware release.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 31, 2026CISA-ADP
Assessed Jul 31, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Tristerjh/Tenda/blob/main/Tenda_W6-S_GO_overflow.md | CISA-ADP | ExploitTechnical Analysis |
| https://github.com/Tristerjh/Tenda/blob/main/Tenda_W6-S_GO_overflow.md | [email protected] | ExploitTechnical Analysis |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-121 | Stack-based Buffer Overflow | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Tenda W6-S | v1.0.0.4(510) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 31, 2026 | CVE Modified | CISA-ADP |
| Jul 31, 2026 | New CVE Received | [email protected] |
Volerion