CVE-2026-1638: Tenda AC21 mDMZSetCfg command injection
A security flaw has been discovered in Tenda AC21 1.1.1.1/1.dmzip/16.03.08.16. The impacted element is the function mDMZSetCfg of the file /goform/mDMZSetCfg. The manipulation of the argument dmzIp results in command injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1638?
CVE-2026-1638 is classified as a high-severity vulnerability due to its potential for remote command injection.
How do I fix CVE-2026-1638?
To remediate CVE-2026-1638, update the Tenda AC21 firmware to the latest version provided by the vendor.
What type of attack is possible with CVE-2026-1638?
CVE-2026-1638 could allow an attacker to execute arbitrary commands on the affected device remotely.
Which devices are affected by CVE-2026-1638?
CVE-2026-1638 affects the Tenda AC21 routers with specific firmware versions.
What component of the Tenda AC21 is vulnerable in CVE-2026-1638?
The mDMZSetCfg function in the /goform/mDMZSetCfg file is the vulnerable component in CVE-2026-1638.