CVE-2026-51843 Details
Description
Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the wanMTU parameter.
A stack buffer overflow vulnerability has been identified in the Tenda AC7 router running firmware version 15.03.06.44, and likely earlier versions. The vulnerability exists in the '/goform/AdvSetMacMtuWan' interface, where the 'wanMTU' parameter can be exploited. The issue arises because the 'wanMTU' parameter is copied into a stack buffer using the unsafe 'strcpy' function, which does not validate the length of the input. This flaw allows attackers to send overly long 'wanMTU' values, leading to a stack buffer overflow. Exploitation of this vulnerability could result in remote arbitrary code execution on the affected device, or cause a denial-of-service condition.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.kdev.site/cve-request_008/ | CISA-ADP | ExploitThird Party Advisory |
| https://www.kdev.site/cve-request_008/ | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-121 | Stack-based Buffer Overflow | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| tenda ac7 firmware | 15.03.06.44 |
CPE
Remediation
| |
| tenda ac7 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 9, 2026 | Initial Analysis | [email protected] |
| Jun 22, 2026 | CVE Modified | CISA-ADP |
| Jun 19, 2026 | New CVE Received | [email protected] |