CVE-2026-24441: Tenda AC7 Transmits Admin Credentials Without HTTPS Protection
Shenzhen Tenda AC7 firmware version V03.03.03.01cn and prior expose account credentials in plaintext within HTTP responses, allowing an on-path attacker to obtain sensitive authentication material.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24441?
CVE-2026-24441 is classified as a high severity vulnerability due to the transmission of admin credentials in plaintext.
How do I fix CVE-2026-24441?
To fix CVE-2026-24441, you should update the Tenda AC7 firmware to a version that supports HTTPS protection.
What types of devices are affected by CVE-2026-24441?
CVE-2026-24441 affects the Tenda AC7 router running firmware version V03.03.03.01_cn or earlier.
What are the risks associated with CVE-2026-24441?
The risks include potential on-path attacks where attackers can intercept and obtain sensitive admin credentials.
Is it safe to use Tenda AC7 with CVE-2026-24441?
Using Tenda AC7 with CVE-2026-24441 is not safe until the firmware is updated to eliminate the plaintext transmission of credentials.