CVE-2026-51846: Tenda AC7 Firmware

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

In Tenda AC7 v15.03.06.44, the wanSpeed parameter of the route /goform/AdvSetMacMtuWan has a stack buffer overflow vulnerability that can lead to remote arbitrary code execution.

Affected products

  • Tenda AC7 Firmware: version 15.03.06.44 only

Published 2026-06-19. Last modified 2026-07-09.