CVE-2026-2147: Tenda AC21 Firmware

Medium severity, CVSS 5.3. EPSS: 0.6% chance of exploitation in the next 30 days.

A weakness has been identified in Tenda AC21 16.03.08.16. This impacts an unknown function of the file /cgi-bin/DownloadLog of the component Web Management Interface. Executing a manipulation can lead to information disclosure. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.

Affected products

  • Tenda AC21 Firmware: version 16.03.08.16 only

Published 2026-02-08. Last modified 2026-06-17.