Security Advisory

CVE-2026-19823

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-14 12:15:10
Last updated 2026-08-18 13:39:11
Assigner VulDB
CVSS score 9.0
State PUBLISHED

Description

A security flaw has been discovered in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. Impacted is the function formQOSRuleDel of the file /goform/delQos of the component QoS Rule Deletion. Performing a manipulation of the argument qosIndex results in stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.