Tenda AC7是中国腾达(Tenda)公司的一款无线路由器。 Tenda AC7 V03.03.03.01_cn及之前版本存在跨站请求伪造漏洞,该漏洞源于Web管理界面未实施CSRF保护,可能导致修改路由器设置。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Shenzhen Tenda Technology Co., Ltd. | Tenda AC7 | ≤ 03.03.03.01_cn |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Shenzhen Tenda Technology Co., Ltd. | Tenda AC7 | 0 ~ 03.03.03.01_cn | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-24441 | Tenda AC7 Transmits Admin Credentials Without HTTPS Protection | |
| CVE-2026-24426 | Tenda AC7 Reflected XSS via Web Interface Output Encoding | |
| CVE-2026-24427 | Tenda AC7 Exposes Admin Credentials in Configuration Responses |
No comments yet