CVE-2026-104611: Tenda AC9 POST Request fast_setting_internet_set stack-based overflow
A vulnerability was detected in Tenda AC9 15.03.02.13. Affected is an unknown function of the file /goform/fastsettinginternetset of the component POST Request Handler. Performing a manipulation of the argument netWanType results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The vulnerable handler is reachable through a POST request, and the attack can be performed remotely. However, the supplied severity vector indicates high privileges are required; the available data does not specify what level or type of privileges those are.
Which systems are known to be affected?
The provided information identifies Tenda AC9 firmware version 15.03.02.13. No other models, firmware versions, or default-configuration details are provided.
How urgent is remediation?
This is rated critical with a 9.1 severity score, and successful exploitation can affect confidentiality, integrity, and availability across a changed scope. A public exploit is reported to exist, increasing the likelihood of active exploitation attempts.
How can I determine whether a device may be affected?
Identify Tenda AC9 devices and check whether they run firmware version 15.03.02.13. The available information does not provide a reliable network indicator, log signature, or other method to confirm exploitation.