PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-51843 Tenda CVE debrief

CVE-2026-51843 is a stack buffer overflow vulnerability in Tenda AC7 v15.03.06.44. The vulnerability exists in the /goform/AdvSetMacMtuWan interface via the wanMTU parameter. This issue may allow attackers to execute arbitrary code. Affected users should review and apply patches from the vendor. The CVE was published on 2026-06-19 and has not been modified since then. The vulnerability's severity and impact are still being assessed.

Vendor
Tenda
Product
AC7
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-19
Original CVE updated
2026-06-22
Advisory published
2026-06-19
Advisory updated
2026-06-22

Who should care

Network administrators and security teams responsible for managing Tenda AC7 devices should be aware of this vulnerability. They should review the device's configuration, assess exposure, and apply patches or mitigations as needed. Additionally, security teams should monitor for potential exploitation attempts.

Technical summary

The CVE-2026-51843 vulnerability is a stack buffer overflow issue in the /goform/AdvSetMacMtuWan interface of Tenda AC7 v15.03.06.44. The vulnerability is caused by the lack of proper validation of the wanMTU parameter. This could allow an attacker to send crafted requests to the device, potentially leading to arbitrary code execution.

Defensive priority

Apply patches or updates from the vendor as soon as available. Limit exposure by restricting access to the /goform/AdvSetMacMtuWan interface.

Recommended defensive actions

  • Inventory Tenda AC7 devices and verify their version.
  • Review and apply patches from the vendor.
  • Limit exposure by restricting access to the /goform/AdvSetMacMtuWan interface.
  • Monitor for potential exploitation attempts.
  • Implement compensating controls, such as Web Application Firewalls (WAFs), to detect and prevent attacks.

Evidence notes

The CVE-2026-51843 vulnerability was published on 2026-06-19. The primary evidence comes from the NVD and CVE.org. The affected product is Tenda AC7 v15.03.06.44. The vulnerability exists in the /goform/AdvSetMacMtuWan interface via the wanMTU parameter. Defenders should verify the device's version and configuration.

Official resources

This article is AI-assisted and based on the supplied source corpus.