CVE-2026-2148: Tenda AC21 Web Management DownloadFlash information disclosure
A security vulnerability has been detected in Tenda AC21 16.03.08.16. Affected is an unknown function of the file /cgi-bin/DownloadFlash of the component Web Management Interface. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2148?
CVE-2026-2148 has a moderate severity rating due to the potential for information disclosure.
How do I fix CVE-2026-2148?
To fix CVE-2026-2148, update the Tenda AC21 firmware to the latest version provided by the vendor.
What type of vulnerability is CVE-2026-2148?
CVE-2026-2148 is an information disclosure vulnerability affecting the Tenda AC21 web management interface.
Which component is affected by CVE-2026-2148?
CVE-2026-2148 affects the /cgi-bin/DownloadFlash function within the web management interface of the Tenda AC21.
Is CVE-2026-2148 specific to any version of Tenda AC21?
Yes, CVE-2026-2148 specifically affects Tenda AC21 version 16.03.08.16.