CVE-2026-24427
- EPSS 0.01%
- Veröffentlicht 03.02.2026 19:16:16
- Zuletzt bearbeitet 10.02.2026 14:12:30
Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior expose sensitive information in web management responses. Administrative credentials, including the router and/or admin panel password, are included in plaintext within configuration respo...
CVE-2026-24426
- EPSS 0.03%
- Veröffentlicht 03.02.2026 19:16:16
- Zuletzt bearbeitet 10.02.2026 14:13:03
Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior contain an improper output encoding vulnerability in the web management interface. User-supplied input is reflected in HTTP responses without adequate escaping, allowing injection of arbit...
CVE-2026-24441
- EPSS 0.01%
- Veröffentlicht 03.02.2026 19:14:41
- Zuletzt bearbeitet 10.02.2026 14:10:35
Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior expose account credentials in plaintext within HTTP responses, allowing an on-path attacker to obtain sensitive authentication material.
CVE-2026-24434
- EPSS 0.01%
- Veröffentlicht 03.02.2026 19:13:01
- Zuletzt bearbeitet 10.02.2026 14:11:25
Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior does not implement CSRF protections for administrative functions in the web management interface. The interface does not enforce anti-CSRF tokens or robust origin validation, which can all...
CVE-2025-11586
- EPSS 0.15%
- Veröffentlicht 10.10.2025 21:16:06
- Zuletzt bearbeitet 20.10.2025 15:50:18
A vulnerability was determined in Tenda AC7 15.03.06.44. This affects an unknown function of the file /goform/setNotUpgrade. This manipulation of the argument newVersion causes stack-based buffer overflow. The attack is possible to be carried out rem...
- EPSS 0.14%
- Veröffentlicht 09.10.2025 03:02:07
- Zuletzt bearbeitet 09.10.2025 22:16:40
A vulnerability was identified in Tenda AC7 15.03.06.44. This affects an unknown function of the file /goform/saveAutoQos. The manipulation of the argument enable leads to stack-based buffer overflow. Remote exploitation of the attack is possible. Th...
- EPSS 0.14%
- Veröffentlicht 09.10.2025 02:32:13
- Zuletzt bearbeitet 24.02.2026 07:16:36
A vulnerability was determined in Tenda AC7 15.03.06.44. The impacted element is an unknown function of the file /goform/fast_setting_pppoe_set. Executing a manipulation of the argument Password can lead to stack-based buffer overflow. The attack may...
- EPSS 0.15%
- Veröffentlicht 09.10.2025 02:32:10
- Zuletzt bearbeitet 24.02.2026 07:16:36
A vulnerability was found in Tenda AC7 15.03.06.44. The affected element is an unknown function of the file /goform/WifiMacFilterSet. Performing a manipulation of the argument wifi_chkHz results in stack-based buffer overflow. The attack may be initi...
CVE-2025-11525
- EPSS 0.15%
- Veröffentlicht 09.10.2025 01:32:06
- Zuletzt bearbeitet 09.10.2025 22:17:13
A vulnerability has been found in Tenda AC7 15.03.06.44. Impacted is an unknown function of the file /goform/SetUpnpCfg. Such manipulation of the argument upnpEn leads to stack-based buffer overflow. The attack can be launched remotely. The exploit h...
CVE-2025-11524
- EPSS 0.14%
- Veröffentlicht 09.10.2025 01:02:11
- Zuletzt bearbeitet 09.10.2025 22:16:55
A flaw has been found in Tenda AC7 15.03.06.44. This issue affects some unknown processing of the file /goform/SetDDNSCfg. This manipulation of the argument ddnsEn causes stack-based buffer overflow. The attack can be initiated remotely. The exploit ...