Vulnerability Description
Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior expose account credentials in plaintext within HTTP responses, allowing an on-path attacker to obtain sensitive authentication material.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tenda | Ac7 Firmware | <= 03.03.03.01 |
| Tenda | Ac7 | - |
Related Weaknesses (CWE)
References
- https://www.tendacn.com/product/AC7Product
- https://www.vulncheck.com/advisories/tenda-ac7-transmits-admin-credentials-withoThird Party Advisory
FAQ
What is CVE-2026-24441?
CVE-2026-24441 is a vulnerability with a CVSS score of 5.9 (MEDIUM). Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior expose account credentials in plaintext within HTTP responses, allowing an on-path attacker to obtain sensitive authentication material.
How severe is CVE-2026-24441?
CVE-2026-24441 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-24441?
Check the references section above for vendor advisories and patch information. Affected products include: Tenda Ac7 Firmware, Tenda Ac7.