CVE-2026-1637

8.8

Tenda · AC21

A stack-based buffer overflow in the Tenda AC21 router allows remote code execution via manipulation of the AdvSetMacMtuWan function.

Executive summary

A critical stack-based buffer overflow vulnerability in Tenda AC21 firmware exposes the device to remote code execution and potential system compromise.

Vulnerability

The flaw exists within the fromAdvSetMacMtuWan function located in the /goform/AdvSetMacMtuWan endpoint, where improper input handling leads to a stack-based buffer overflow. An attacker with low-level privileges can trigger this memory corruption to execute arbitrary code remotely.

Business impact

Successful exploitation of this vulnerability allows an attacker to achieve full control over the affected network device. Given the CVSS score of 8.8, this poses a high risk of unauthorized network access, potential data interception, and lateral movement within the local network environment. Organizations relying on this hardware for connectivity face significant risks of service disruption and security compromise.

Remediation

Immediate Action: Contact Tenda support or check the official Tenda website for firmware updates addressing this buffer overflow, as a specific patch version is not currently provided in public records.

Proactive Monitoring: Monitor network traffic for anomalous requests directed toward the /goform/AdvSetMacMtuWan endpoint and examine device logs for signs of unexpected reboots or crashes.

Compensating Controls: Implement strict access control lists on the management interface and place the device behind a firewall to restrict access to the web management console from untrusted networks.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the linked GitHub repository.

Analyst recommendation

The severity of this vulnerability, combined with the availability of a public proof-of-concept, necessitates immediate action. Administrators must restrict access to the vulnerable interface immediately and prioritize the deployment of vendor-supplied firmware updates as soon as they become available to prevent potential remote compromise of the network infrastructure.

More Tenda CVEs

Sources

Originally found and disclosed by LX-LX (VulDB User), per the CVE Program record.