CVE-2026-51845: Buffer Overflow
Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the mac parameter.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable remote (WAN-side) web management access to the router so the /goform/AdvSetMacMtuWan interface is not reachable from untrusted networks.
Tenda AC7 web management remote_management = disabled - Compensating control
At the network perimeter or on intermediate firewalls/WAFs, block or filter requests to the /goform/AdvSetMacMtuWan path and/or the router's web management port; restrict access to the management interface to trusted IPs, VLANs, or an isolated management network.
- Operational
Monitor router/web-management logs for requests to /goform/AdvSetMacMtuWan or signs of exploitation and, if suspicious activity is detected, isolate the device for investigation and remediation.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-51845?
CVE-2026-51845 has a risk score of 71, indicating a high severity vulnerability.
How do I fix CVE-2026-51845?
To fix CVE-2026-51845, update the Tenda AC7 firmware to the latest version provided by the manufacturer.
Who is affected by CVE-2026-51845?
CVE-2026-51845 affects users of Tenda AC7 devices running version 15.03.06.44.
What type of vulnerability is CVE-2026-51845?
CVE-2026-51845 is classified as a stack buffer overflow vulnerability.
What is the impact of CVE-2026-51845?
CVE-2026-51845 can lead to potential remote code execution due to the buffer overflow in the mac parameter.