CVE-2026-2147: Tenda AC21 Web Management DownloadLog information disclosure
A weakness has been identified in Tenda AC21 16.03.08.16. This impacts an unknown function of the file /cgi-bin/DownloadLog of the component Web Management Interface. Executing a manipulation can lead to information disclosure. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2147?
The severity of CVE-2026-2147 is considered moderate due to the potential for information disclosure.
How do I fix CVE-2026-2147?
Fixing CVE-2026-2147 involves updating the firmware of Tenda AC21 to the latest version recommended by the vendor.
What type of vulnerability is CVE-2026-2147?
CVE-2026-2147 is classified as an information disclosure vulnerability.
What component is affected by CVE-2026-2147?
CVE-2026-2147 affects the Web Management Interface of the Tenda AC21 router.
How can CVE-2026-2147 be exploited?
CVE-2026-2147 can be exploited by manipulating requests to the /cgi-bin/DownloadLog endpoint, potentially revealing sensitive information.