CVE-2026-24427: Tenda AC7 Exposes Admin Credentials in Configuration Responses
Shenzhen Tenda AC7 firmware version V03.03.03.01cn and prior expose sensitive information in web management responses. Administrative credentials, including the router and/or admin panel password, are included in plaintext within configuration response bodies. In addition, responses lack appropriate Cache-Control directives, which may permit web browsers to cache pages containing these credentials and enable subsequent disclosure to an attacker with access to the client system or browser profile.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24427?
CVE-2026-24427 is considered a high severity vulnerability due to the exposure of sensitive administrative credentials.
How do I fix CVE-2026-24427?
To fix CVE-2026-24427, upgrade the Tenda AC7 firmware to a version higher than V03.03.03.01_cn.
What does CVE-2026-24427 affect?
CVE-2026-24427 affects the Tenda AC7 router and its associated firmware versions that have not been updated.
What information is exposed in CVE-2026-24427?
CVE-2026-24427 exposes sensitive administrative credentials in plaintext within the configuration responses of the Tenda AC7 web management interface.
How can I identify if my device is vulnerable to CVE-2026-24427?
You can identify if your device is vulnerable to CVE-2026-24427 by checking if it is running Tenda AC7 firmware version V03.03.03.01_cn or older.