PatchSiren cyber security CVE debrief
CVE-2026-51843 Tenda CVE debrief
CVE-2026-51843 is a stack buffer overflow vulnerability in Tenda AC7 v15.03.06.44. The vulnerability exists in the /goform/AdvSetMacMtuWan interface via the wanMTU parameter. This issue may allow attackers to execute arbitrary code. Affected users should review and apply patches from the vendor. The CVE was published on 2026-06-19 and has not been modified since then. The vulnerability's severity and impact are still being assessed.
- Vendor
- Tenda
- Product
- AC7
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-19
- Original CVE updated
- 2026-06-22
- Advisory published
- 2026-06-19
- Advisory updated
- 2026-06-22
Who should care
Network administrators and security teams responsible for managing Tenda AC7 devices should be aware of this vulnerability. They should review the device's configuration, assess exposure, and apply patches or mitigations as needed. Additionally, security teams should monitor for potential exploitation attempts.
Technical summary
The CVE-2026-51843 vulnerability is a stack buffer overflow issue in the /goform/AdvSetMacMtuWan interface of Tenda AC7 v15.03.06.44. The vulnerability is caused by the lack of proper validation of the wanMTU parameter. This could allow an attacker to send crafted requests to the device, potentially leading to arbitrary code execution.
Defensive priority
Apply patches or updates from the vendor as soon as available. Limit exposure by restricting access to the /goform/AdvSetMacMtuWan interface.
Recommended defensive actions
- Inventory Tenda AC7 devices and verify their version.
- Review and apply patches from the vendor.
- Limit exposure by restricting access to the /goform/AdvSetMacMtuWan interface.
- Monitor for potential exploitation attempts.
- Implement compensating controls, such as Web Application Firewalls (WAFs), to detect and prevent attacks.
Evidence notes
The CVE-2026-51843 vulnerability was published on 2026-06-19. The primary evidence comes from the NVD and CVE.org. The affected product is Tenda AC7 v15.03.06.44. The vulnerability exists in the /goform/AdvSetMacMtuWan interface via the wanMTU parameter. Defenders should verify the device's version and configuration.
Official resources
-
CVE-2026-51843 CVE record
CVE.org
-
CVE-2026-51843 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
This article is AI-assisted and based on the supplied source corpus.