PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-51846 Tenda CVE debrief

CVE-2026-51846 is a stack buffer overflow vulnerability in the Tenda AC7 router, specifically in the wanSpeed parameter of the /goform/AdvSetMacMtuWan route. This vulnerability, present in version 15.03.06.44, could allow for remote arbitrary code execution. The CVE was published on June 19, 2026. Given the potential for remote code execution, defenders should prioritize patching or mitigating this vulnerability. The disclosure of this CVE is based on information from official sources and is AI-assisted.

Vendor
Tenda
Product
AC7
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-19
Original CVE updated
2026-07-09
Advisory published
2026-06-19
Advisory updated
2026-07-09

Who should care

Organizations using Tenda AC7 routers, specifically version 15.03.06.44, should be aware of this vulnerability and take steps to mitigate or patch it. This includes network administrators, cybersecurity teams, and IT professionals responsible for maintaining network infrastructure. The potential for remote arbitrary code execution makes this a high-priority vulnerability to address.

Technical summary

The CVE-2026-51846 vulnerability is a stack buffer overflow issue in the Tenda AC7 router. It is located in the wanSpeed parameter of the /goform/AdvSetMacMtuWan route. This type of vulnerability occurs when more data is written to a buffer than it is designed to hold, causing adjacent memory to be overwritten. In this case, the vulnerability could potentially allow for remote arbitrary code execution, giving an attacker control over the affected system. The vulnerability is present in Tenda AC7 version 15.03.06.44.

Defensive priority

High priority due to potential for remote arbitrary code execution

Recommended defensive actions

  • Inventory Tenda AC7 routers and verify version 15.03.06.44 is in use
  • Review official vendor advisories for patches or mitigations
  • Apply patches or updates if available
  • Implement compensating controls such as network segmentation or access restrictions
  • Monitor network activity for suspicious behavior related to the Tenda AC7

Evidence notes

The primary evidence for this CVE comes from official sources, including the CVE.org record and the National Vulnerability Database (NVD). The vulnerability is described as a stack buffer overflow in the wanSpeed parameter of the /goform/AdvSetMacMtuWan route in Tenda AC7 version 15.03.06.44. The evidence suggests that this vulnerability could lead to remote arbitrary code execution. Defenders should verify the affected product and version with official sources.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-51846 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-51846

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-51846 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-51846

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.