High severity8.8NVD Advisory· Published Apr 10, 2026· Updated Apr 30, 2026
CVE-2026-6016
CVE-2026-6016
Description
A vulnerability was found in Tenda AC9 15.03.02.13. The affected element is the function decodePwd of the file /goform/WizardHandle of the component POST Request Handler. Performing a manipulation of the argument WANS results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made public and could be used.
Affected products
1- cpe:2.3:o:tenda:ac9_firmware:15.03.02.13:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- lavender-bicycle-a5a.notion.site/Tenda-AC9-WizardHandle-33153a41781f808480f9e3b78ce438e0nvdExploitThird Party Advisory
- vuldb.com/submit/791829nvdThird Party AdvisoryVDB Entry
- vuldb.com/vuln/356572nvdThird Party AdvisoryVDB Entry
- vuldb.com/vuln/356572/ctinvdPermissions RequiredVDB Entry
- www.tenda.com.cnnvdProduct
News mentions
0No linked articles in our index yet.