CVE-2026-51846: Buffer Overflow
In Tenda AC7 v15.03.06.44, the wanSpeed parameter of the route /goform/AdvSetMacMtuWan has a stack buffer overflow vulnerability that can lead to remote arbitrary code execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable WAN-side/remote web management or restrict it to a small set of trusted management IP addresses to prevent remote access to management endpoints such as /goform/AdvSetMacMtuWan.
Tenda AC7 web management remote_web_management (WAN access) = disabled or restricted to trusted IPs - Compensating control
Block or filter access to the HTTP path /goform/AdvSetMacMtuWan (and specifically requests setting the wanSpeed parameter) at the network edge (WAF, reverse proxy, or firewall) to prevent remote exploitation.
- Operational
If any device is running Tenda AC7 v15.03.06.44, isolate it from untrusted networks (remove WAN/Internet access or place on an isolated management VLAN) and plan to remove/replace or keep offline until an official vendor firmware fix is available.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-51846?
CVE-2026-51846 has a CVSS score of 89, indicating a high severity level due to its potential for remote arbitrary code execution.
How do I fix CVE-2026-51846?
To fix CVE-2026-51846, update the Tenda AC7 firmware to the latest version provided by the vendor.
What does CVE-2026-51846 affect?
CVE-2026-51846 affects the Tenda AC7 router, specifically the wanSpeed parameter in the AdvSetMacMtuWan function.
What kind of vulnerability is CVE-2026-51846?
CVE-2026-51846 is classified as a buffer overflow vulnerability, which can lead to arbitrary code execution on the affected system.
When was CVE-2026-51846 published?
CVE-2026-51846 was published on June 19, 2026.