Vulnerability Description
Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior contain an improper output encoding vulnerability in the web management interface. User-supplied input is reflected in HTTP responses without adequate escaping, allowing injection of arbitrary HTML or JavaScript in a victim’s browser context.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tenda | Ac7 Firmware | <= 03.03.03.01 |
| Tenda | Ac7 | - |
Related Weaknesses (CWE)
References
- https://www.tendacn.com/product/AC7Product
- https://www.vulncheck.com/advisories/tenda-ac7-reflected-xss-via-web-interface-oThird Party Advisory
FAQ
What is CVE-2026-24426?
CVE-2026-24426 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior contain an improper output encoding vulnerability in the web management interface. User-supplied input is reflected in HTTP responses with...
How severe is CVE-2026-24426?
CVE-2026-24426 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-24426?
Check the references section above for vendor advisories and patch information. Affected products include: Tenda Ac7 Firmware, Tenda Ac7.