FAIL › dossier
ac7
PRODUCT· dossier confidence 50%
Tenda AC7 wireless routers are critically vulnerable to remote code execution via multiple unpatched stack buffer overflows in their web management interface, allowing attackers to execute arbitrary code on the device.
PROFILE
Categorynetworking hardwareWhat they doTenda AC7 is a wireless router manufactured by Tenda Technology.
SECURITY POSTURE
The Tenda AC7 exhibits a severe lack of input validation and memory safety in its web management interface, resulting in multiple critical RCE vulnerabilities on the same day.
Notable failures
- CVE-2026-51846: RCE0day via wanSpeed stack buffer overflow
- CVE-2026-51843: RCE via wanMTU stack buffer overflow
- CVE-2026-51845: RCE via mac stack buffer overflow
- CVE-2026-51844: RCE via cloneType stack buffer overflow
Patterns: repeated unpatched edge-device RCEs; stack buffer overflows in web management interfaces
FAILURE HISTORY · 4
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-06-19 | CVE-2026-51846 | critical | In Tenda AC7 v15.03.06.44, the wanSpeed parameter of the route /goform/AdvSetMacMtuWan has a stack buffer overflow vulnerability that can lead to remote arbitrary code execution. |
| 2026-06-19 | CVE-2026-51843 | critical | Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the wanMTU parameter. |
| 2026-06-19 | CVE-2026-51845 | critical | Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the mac parameter. |
| 2026-06-19 | CVE-2026-51844 | critical | Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the cloneType parameter. |
Open questions: Tenda's patch response time for these vulnerabilities · Whether these vulnerabilities were actively exploited in the wild
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-18 04:06:28.771545+00:00