CVE Tools

CVE-2026-19824

Tenda W20E addIpMacBind ipMacBindListStore stack-based overflow

Published: Aug 14, 2026Updated: Aug 14, 2026 Sources: CVE List NVDCWE-119

Description

A weakness has been identified in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. The affected element is the function ipMacBindListStore of the file /goform/addIpMacBind. Executing a manipulation of the argument IPMacBindRule can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.

In plain language

AI Worth attention

CVE-2026-19824 is a security flaw in Tenda W20E that can let someone with a basic login crash or fully control the router from the network; if you expose the router admin to the internet or have weak/unused accounts, you should take action now.

Executive summary

CVE-2026-19824 is a stack-based overflow (CWE-119/CWE-121) in the Tenda W20E IP–MAC binding feature (ipMacBindListStore via /goform/addIpMacBind), where a remotely reachable attacker with low-level login can send crafted input to gain full control or cause denial of service.

If affected, business impact
Full router takeoverInternet outage via crashesNetwork traffic interception riskLoss of business connectivity

What to do now

  1. Check your router model is exactly Tenda W20E and your firmware matches 15.11.0.6(1068_1546_841)_CN_TDC.
  2. If you use the router remotely (especially from the internet), immediately restrict access so the admin/login pages are only reachable from your local network.
  3. Remove or lock down any low-privilege accounts, and change the passwords for all router accounts to strong, unique passwords.
  4. Look for a vendor firmware update for Tenda W20E specifically addressing CVE-2026-19824; no fixed version is currently identified in the available records.
  5. If you cannot patch, create a temporary “containment” plan: use a separate firewall/VPN for remote access to your network, and keep the router’s management interface off the public internet.
May need vendor / contractor work

CVSS Vector Breakdown

AV:NAC:LPR:LUI:NS:UC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:LPrivileges Required
Low
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

Exploitability

No known exploits, KEV entries, or remediation guidance available for this vulnerability yet.

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

2 techniques
Initial Access
Privilege Escalation
View detailed technique mapping

References

and 3 more references View all →

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-19824 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store