PT-2026-5372 · Tenda · Tenda Ac21

Lx-Lx

·

Published

2026-01-29

·

Updated

2026-01-30

·

CVE-2026-1638

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tenda AC21 versions 1.1.1.1/1.dmzip/16.03.08.16
Description A security flaw exists in the Tenda AC21 router. The issue is related to command injection within the mDMZSetCfg function, located in the /goform/mDMZSetCfg file. Manipulation of the dmzIp argument can lead to remote code execution. The exploit for this issue has been publicly released and may be used in attacks.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the /goform/mDMZSetCfg file.

Exploit

Fix

Special Elements Injection

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-1638

Affected Products

Tenda Ac21