CVE-2026-24434: Tenda AC7 Web Interface Lacks CSRF Protections for Admin Actions
Shenzhen Tenda AC7 firmware version V03.03.03.01cn and prior does not implement CSRF protections for administrative functions in the web management interface. The interface does not enforce anti-CSRF tokens or robust origin validation, which can allow an attacker to induce a logged-in administrator to perform unintended state-changing requests and modify router settings.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24434?
The severity of CVE-2026-24434 is rated as high due to the lack of CSRF protections that could allow unauthorized actions in the Tenda AC7 web management interface.
How do I fix CVE-2026-24434?
To fix CVE-2026-24434, update the Tenda AC7 firmware to the latest version that implements CSRF protections.
What versions of Tenda AC7 are affected by CVE-2026-24434?
The affected versions of Tenda AC7 are V03.03.03.01_cn and earlier.
What type of vulnerability is CVE-2026-24434?
CVE-2026-24434 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the web interface of Tenda AC7.
Can CVE-2026-24434 lead to unauthorized access?
Yes, CVE-2026-24434 can lead to unauthorized access to administrative functions in the Tenda AC7 web interface.