EXPOSURES › CVE-2021-31755
CVE-2021-31755
HIGH ⌖ ON CISA KEV · EXPLOITEDTenda AC11 routers have an unpatched stack buffer overflow allowing remote code execution via a crafted HTTP request.
The Tenda AC11 router's web management interface lacks input validation and memory safety, enabling attackers to execute arbitrary code without authentication. This exposes networks to malware, ransomware, and data theft, directly impacting DIB compliance by violating NIST 800-171 controls for system integrity and access control. Organizations must replace or patch these devices immediately and audit similar Tenda hardware for unpatched CVEs.
Shame score — Tenda shipped routers with a critical, unpatched RCE vulnerability that was actively exploited in the wild, demonstrating severe negligence in supply-chain security and post-market patching.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Tenda AC11 devices contain a stack buffer overflow vulnerability in /goform/setmac which allows attackers to execute code via a crafted post request.
"Tenda AC11 devices contain a stack buffer overflow vulnerability in /goform/setmac which allows attackers to execute code via a crafted post request."