Skip to content
COOEY

EXPOSURES › CVE-2021-31755

CVE-2021-31755

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-31755 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 exploited-in-wildunpatchedrce

Tenda AC11 routers have an unpatched stack buffer overflow allowing remote code execution via a crafted HTTP request.

The Tenda AC11 router's web management interface lacks input validation and memory safety, enabling attackers to execute arbitrary code without authentication. This exposes networks to malware, ransomware, and data theft, directly impacting DIB compliance by violating NIST 800-171 controls for system integrity and access control. Organizations must replace or patch these devices immediately and audit similar Tenda hardware for unpatched CVEs.

Shame score — Tenda shipped routers with a critical, unpatched RCE vulnerability that was actively exploited in the wild, demonstrating severe negligence in supply-chain security and post-market patching.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Tenda AC11 devices contain a stack buffer overflow vulnerability in /goform/setmac which allows attackers to execute code via a crafted post request.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Vulnerability allows remote code execution, a critical flaw with severe security implications.
cooey ↗ severe-fallout -0.60
Critical flaw allowing remote code execution.
"Tenda AC11 devices contain a stack buffer overflow vulnerability in /goform/setmac which allows attackers to execute code via a crafted post request."
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.