{"id":"CVE-2026-90688","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-90688","summary":"A vulnerability was identified in Tenda W20E 15.11.0.61068_1546_841_CN_TDC. This issue affects the function formIPMacBindAdd of the component HTTP Handler. Such manipulation of the…","details":"A vulnerability was identified in Tenda W20E 15.11.0.61068_1546_841_CN_TDC. This issue affects the function formIPMacBindAdd of the component HTTP Handler. Such manipulation of the argument IPMacBindRule leads to stack-based buffer overflow. It is possible to launch the attack remotely.","published":"2026-09-14T07:17:24.513","modified":"2026-09-15T16:17:39.990","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://github.com/Amalll-Sec/router-vulnerability-research/blob/main/advisories/Tenda/W20E/formIPMacBindAdd/README.md"},{"type":"WEB","url":"https://vuldb.com/cve/CVE-2026-90688"},{"type":"WEB","url":"https://vuldb.com/submit/914958"},{"type":"WEB","url":"https://vuldb.com/vuln/403221"},{"type":"WEB","url":"https://vuldb.com/vuln/403221/cti"},{"type":"WEB","url":"https://www.tenda.com.cn/"},{"type":"WEB","url":"https://github.com/Amalll-Sec/router-vulnerability-research/blob/main/advisories/Tenda/W20E/formIPMacBindAdd/README.md"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-15T16:17:39.990"}}