Vulnerability Description
Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior does not implement CSRF protections for administrative functions in the web management interface. The interface does not enforce anti-CSRF tokens or robust origin validation, which can allow an attacker to induce a logged-in administrator to perform unintended state-changing requests and modify router settings.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tenda | Ac7 Firmware | <= 03.03.03.01 |
| Tenda | Ac7 | - |
Related Weaknesses (CWE)
References
- https://www.tendacn.com/product/AC7Product
- https://www.vulncheck.com/advisories/tenda-ac7-web-interface-lacks-csrf-protectiThird Party Advisory
FAQ
What is CVE-2026-24434?
CVE-2026-24434 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior does not implement CSRF protections for administrative functions in the web management interface. The interface does not enforce anti-CSRF...
How severe is CVE-2026-24434?
CVE-2026-24434 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-24434?
Check the references section above for vendor advisories and patch information. Affected products include: Tenda Ac7 Firmware, Tenda Ac7.