CVE-2026-24434

MEDIUM

Shenzhen Tenda AC7 <V03.03.03.01_cn - CSRF

Title source: llm

Description

Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior does not implement CSRF protections for administrative functions in the web management interface. The interface does not enforce anti-CSRF tokens or robust origin validation, which can allow an attacker to induce a logged-in administrator to perform unintended state-changing requests and modify router settings.

Scores

CVSS v3 6.5
EPSS 0.0001
EPSS Percentile 0.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Classification

CWE
CWE-352
Status published

Affected Products (1)

tenda/ac7_firmware < 03.03.03.01

Timeline

Published Feb 03, 2026
Tracked Since Feb 18, 2026