CVE-2026-6015
published 2026-04-10CVE-2026-6015: A vulnerability has been found in Tenda AC9 15.03.02.13. Impacted is the function formQuickIndex of the file /goform/QuickIndex of the component POST Request…
PriorityP269high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.81%
53.2th percentile
A vulnerability has been found in Tenda AC9 15.03.02.13. Impacted is the function formQuickIndex of the file /goform/QuickIndex of the component POST Request Handler. Such manipulation of the argument PPPOEPassword leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| tenda | ac9 | — | — |
| tenda | ac9_firmware | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.07.4HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Tenda AC9 15.03.02.13 POST Request /goform/QuickIndex formQuickIndex PPPOEPassword stack-based overflow (EUVD-2026-21311)
vuldb·2026-04-10·CVSS 7.4
CVE-2026-6015 [HIGH] Tenda AC9 15.03.02.13 POST Request /goform/QuickIndex formQuickIndex PPPOEPassword stack-based overflow (EUVD-2026-21311)
A vulnerability was found in Tenda AC9 15.03.02.13 and classified as critical. Impacted is the function formQuickIndex of the file /goform/QuickIndex of the component POST Request Handler. Such manipulation of the argument PPPOEPassword leads to stack-based buffer overflow.
This vulnerability is referenced as CVE-2026-6015. It is possible to launch the attack remotely. Furthermore, an exploit is available.
GHSA
GHSA-9jxj-33wq-5v9p: A vulnerability has been found in Tenda AC9 15
ghsa_unreviewed·2026-04-10
CVE-2026-6015 [HIGH] CWE-119 GHSA-9jxj-33wq-5v9p: A vulnerability has been found in Tenda AC9 15
A vulnerability has been found in Tenda AC9 15.03.02.13. Impacted is the function formQuickIndex of the file /goform/QuickIndex of the component POST Request Handler. Such manipulation of the argument PPPOEPassword leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-10
Published