PT-2026-6190 · Tenda · Tenda Ac7

Kazuma Matsumoto

·

Published

2026-02-03

·

Updated

2026-02-10

·

CVE-2026-24427

CVSS v4.0

6.8

Medium

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Shenzhen Tenda AC7 firmware versions prior to V03.03.03.01 cn
Description The firmware for Shenzhen Tenda AC7 devices up to version V03.03.03.01 cn reveals sensitive information within web management responses. This includes administrative credentials, such as the router and admin panel password, being present in plaintext within configuration response bodies. Furthermore, the responses do not include appropriate Cache-Control directives, potentially allowing web browsers to cache pages containing these credentials, which could lead to disclosure if an attacker gains access to the client system or browser profile.
Recommendations Update to a firmware version newer than V03.03.03.01 cn.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-06995
CVE-2026-24427

Affected Products

Tenda Ac7