Junglewise Threat Intelligence

CVE-2026-51846: Tenda AC7 stack overflow in /goform/AdvSetMacMtuWan

CVE-2026-51846 · Severity: info · CVSS 9.8 · Published 2026-06-19

Technologies: Tenda Ac7. Vendors: Tenda.

Executive brief

The Tenda AC7 is a wireless router used for home and small office networking. A security flaw in its web management interface allows an attacker to send a specially crafted request that can crash the device or take full control of it. This could lead to a complete loss of internet connectivity or allow an unauthorized person to monitor network traffic and access sensitive data.

Technical details

A stack-based buffer overflow exists in Tenda AC7 firmware version v15.03.06.44. The vulnerability is located in the check_param_changed method, which processes the wanSpeed parameter from the /goform/AdvSetMacMtuWan route. The application uses the unsafe strcpy function to copy user-controlled input into a fixed-size stack buffer without proper bounds checking. A remote attacker can exploit this by sending a crafted POST request to the router's web interface, leading to a denial-of-service (DoS) condition or arbitrary code execution (RCE) with elevated privileges.

Affected products

  • Tenda AC7 v15.03.06.44

Timeline

  • 2026-04-30: disclosed: Initial vulnerability report by KDEV
  • 2026-06-19: advisory: CVE published to NVD dataset

References

Related threats