Home

Description

Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the picCropName parameter of the formCropAndSetWewifiPic function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

PUBLISHED Reserved 2026-04-06 | Published 2026-06-09 | Updated 2026-06-09 | Assigner mitre

References

github.com/...mVulLLM/tree/main/W20E/formCropAndSetWewifiPic

cve.org (CVE-2026-36821)

nvd.nist.gov (CVE-2026-36821)

Download JSON