Security Advisory

CVE-2026-67822

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-31 00:00:00
Last updated 2026-07-31 18:18:21
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' parameters into a 64-byte stack buffer without length restriction, leading to stack overflow.