CVE-2026-6016
HIGHA vulnerability was found in Tenda AC9 15.03.02.13. The affected element is the function decodePwd of the file /goform/WizardHandle of the component POST Request Handler. Performing a manipulation of the argument WANS results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made public and could be used.
Published: 4/10/2026Modified: 4/30/2026
Related Intelligence (0)
No articles currently reference this CVE.
References (5)
https://lavender-bicycle-a5a.notion.site/Tenda-AC9-WizardHandle-33153a41781f808480f9e3b78ce438e0?source=copy_linkExploitThird Party Advisoryhttps://vuldb.com/submit/791829Third Party AdvisoryVDB Entryhttps://vuldb.com/vuln/356572Third Party AdvisoryVDB Entryhttps://vuldb.com/vuln/356572/ctiPermissions RequiredVDB Entryhttps://www.tenda.com.cn/Product