CVE-2026-51844 Details
Description
Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the cloneType parameter.
A stack buffer overflow vulnerability has been identified in the Tenda AC7 router running firmware version 15.03.06.44, and likely earlier versions. The vulnerability exists in the '/goform/AdvSetMacMtuWan' interface, where the 'cloneType' parameter is processed by the 'check_param_changed' method. This method uses 'strcpy' to copy the user-controlled data into a stack buffer without proper size validation, leading to a stack overflow. Exploitation of this vulnerability could result in remote arbitrary code execution or a denial-of-service condition.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.kdev.site/cve-request_006/ | CISA-ADP | ExploitThird Party Advisory |
| https://www.kdev.site/cve-request_006/ | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-121 | Stack-based Buffer Overflow | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| tenda ac7 firmware | 15.03.06.44 |
CPE
Remediation
| |
| tenda ac7 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 9, 2026 | Initial Analysis | [email protected] |
| Jun 22, 2026 | CVE Modified | CISA-ADP |
| Jun 19, 2026 | New CVE Received | [email protected] |