CVE-2026-104611: Tenda AC9 POST Request fast_setting_internet_set stack-based overflow

Published Oct 2, 2026
·
Updated

A vulnerability was detected in Tenda AC9 15.03.02.13. Affected is an unknown function of the file /goform/fastsettinginternetset of the component POST Request Handler. Performing a manipulation of the argument netWanType results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.

Affected Software

1 affected component
Tenda Ac9=15.03.02.13

Event History

Oct 2, 2026
CVE Published
via MITRE·12:15 PM
Data Sourced
via MITRE·12:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What access does an attacker need to exploit this issue?

The vulnerable handler is reachable through a POST request, and the attack can be performed remotely. However, the supplied severity vector indicates high privileges are required; the available data does not specify what level or type of privileges those are.

2

Which systems are known to be affected?

The provided information identifies Tenda AC9 firmware version 15.03.02.13. No other models, firmware versions, or default-configuration details are provided.

3

How urgent is remediation?

This is rated critical with a 9.1 severity score, and successful exploitation can affect confidentiality, integrity, and availability across a changed scope. A public exploit is reported to exist, increasing the likelihood of active exploitation attempts.

4

How can I determine whether a device may be affected?

Identify Tenda AC9 devices and check whether they run firmware version 15.03.02.13. The available information does not provide a reliable network indicator, log signature, or other method to confirm exploitation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203