PT-2026-6190 · Tenda · Tenda Ac7
Kazuma Matsumoto
·
Published
2026-02-03
·
Updated
2026-02-10
·
CVE-2026-24427
CVSS v4.0
6.8
Medium
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Shenzhen Tenda AC7 firmware versions prior to V03.03.03.01 cn
Description
The firmware for Shenzhen Tenda AC7 devices up to version V03.03.03.01 cn reveals sensitive information within web management responses. This includes administrative credentials, such as the router and admin panel password, being present in plaintext within configuration response bodies. Furthermore, the responses do not include appropriate Cache-Control directives, potentially allowing web browsers to cache pages containing these credentials, which could lead to disclosure if an attacker gains access to the client system or browser profile.
Recommendations
Update to a firmware version newer than V03.03.03.01 cn.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tenda Ac7