CVE-2026-51843: Buffer Overflow
Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the wanMTU parameter.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict access to the device management interface and block the vulnerable endpoint. Disable remote/web management if possible, limit management access to trusted IPs, and/or deploy firewall/WAF rules to block requests to /goform/AdvSetMacMtuWan or requests that include the wanMTU parameter until a vendor patch is available.
- Operational
Monitor device logs and network traffic for requests to /goform/AdvSetMacMtuWan or unusual WAN MTU configuration activity; isolate or remove affected devices from the network if exploitation is suspected and await vendor remediation.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-51843?
CVE-2026-51843 has a risk rating of 71, indicating it has a high severity level.
How do I fix CVE-2026-51843?
To mitigate CVE-2026-51843, users should update Tenda AC7 firmware to the latest version provided by the manufacturer.
What causes CVE-2026-51843?
CVE-2026-51843 is caused by a stack buffer overflow vulnerability linked to the wanMTU parameter in the /goform/AdvSetMacMtuWan interface.
What are the implications of CVE-2026-51843?
Exploitation of CVE-2026-51843 may allow attackers to execute arbitrary code or cause a denial of service on the affected device.
Is my Tenda AC7 device affected by CVE-2026-51843?
Yes, Tenda AC7 devices running firmware version v15.03.06.44 are affected by CVE-2026-51843.