Title: Tenda AC21 V16.03.08.16 Missing Critical Step in Authentication Description: Tenda AC21 V16.03.08.16 is vulnerable to an Unauthenticated Firmware Download vulnerability. The /cgi-bin/DownloadFlash path lacks Authentication or Authorization checks, allowing a remote attacker to bypass login and access the full firmware binary, potentially revealing sensitive data such as account hashes, hardcoded credentials, or private keys. Source: https://github.com/master-abc/cve/issues/27 Submitter: jiefengliang (UID 93721) Submission Date: 01/27/2026 06:07 PM Moderation Date: 02/07/2026 08:51 AM Status: Accepted VulDB Entry: 2344850 [Tenda AC21 16.03.08.16 Web Management Interface/cgi-bin/DownloadFlash information disclosure] Points: 20