CVE-2026-24434
MEDIUMShenzhen Tenda AC7 <V03.03.03.01_cn - CSRF
Title source: llmDescription
Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior does not implement CSRF protections for administrative functions in the web management interface. The interface does not enforce anti-CSRF tokens or robust origin validation, which can allow an attacker to induce a logged-in administrator to perform unintended state-changing requests and modify router settings.
Scores
CVSS v3
6.5
EPSS
0.0001
EPSS Percentile
0.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Classification
CWE
CWE-352
Status
published
Affected Products (1)
tenda/ac7_firmware
< 03.03.03.01
Timeline
Published
Feb 03, 2026
Tracked Since
Feb 18, 2026