CVE-2026-90689
HIGHCVSS 8.8/10EPSS 0.60%
Last modified
CVE-2026-90689 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A security flaw has been discovered in Tenda W20E 15.11.0.61068_1546_841_CN_TDC. Impacted is the function formDelWebAuthWhiteUser. EPSS estimates a 0.60% chance of exploitation in the next 30 days.
Description
A security flaw has been discovered in Tenda W20E 15.11.0.61068_1546_841_CN_TDC. Impacted is the function formDelWebAuthWhiteUser. Performing a manipulation of the argument webAuthWhiteUserIndex results in stack-based buffer overflow. The attack can be initiated remotely.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Tenda | W20E | 15.11.0.61068_1546_841_CN_TDC |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-90689?
A security flaw has been discovered in Tenda W20E 15.11.0.61068_1546_841_CN_TDC. Impacted is the function formDelWebAuthWhiteUser. Performing a manipulation of the argument webAuthWhiteUserIndex results in stack-based buffer overflow. The attack can be initiated remotely.
How severe is CVE-2026-90689?
CVE-2026-90689 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 0.60% probability of exploitation in the next 30 days.
How do I fix CVE-2026-90689?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-90683A vulnerability was detected in GPAC up to f1219cde. Affecte…3.3
- CVE-2026-90684A flaw has been found in GPAC up to f1219cde. Affected by th…2.8
- CVE-2026-90685A vulnerability has been found in GPAC up to f1219cde. Affec…2.8
- CVE-2026-90686A vulnerability was found in GPAC up to f1219cde. This affec…5.3
- CVE-2026-90687A vulnerability was determined in GPAC up to f1219cde. This …6.3
- CVE-2026-90688A vulnerability was identified in Tenda W20E 15.11.0.61068_1…6.5
- CVE-2026-90690A weakness has been identified in 0x4m4 HexStrike AI up to d…7.3
- CVE-2026-90691A security vulnerability has been detected in 0x4m4 HexStrik…8.3
- CVE-2026-90692A vulnerability was detected in D-Link DIR-878 120B05. This …9.9
- CVE-2026-90693A flaw has been found in D-Link DIR-878 120B05. This impacts…9.9
- CVE-2026-90694A vulnerability has been found in SourceCodester Inventory M…3.5
- CVE-2026-90695A vulnerability was found in SourceCodester Inventory Manage…3.5
Are you affected by CVE-2026-90689?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
