📦 Ac7 Firmware

by Tenda

🔍 What is Ac7 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-29137

CRITICAL CVSS 9.8 Mar 19, 2025

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC7 routers by exploiting a buffer overflow in the timeZone parameter. Attackers can gain full control of affected devices...

CVE-2024-32301

CRITICAL CVSS 9.8 Apr 17, 2024

This CVE describes a stack overflow vulnerability in Tenda AC7V1.0 routers via the PPW parameter in the fromWizardHandle function. Attackers can exploit this to execute arbitrary code or crash the dev...

CVE-2023-41558

CRITICAL CVSS 9.8 Aug 30, 2023

CVE-2023-41558 is a critical stack overflow vulnerability in Tenda AC7 routers that allows remote attackers to execute arbitrary code by sending specially crafted requests to the /goform/SetSysTimeCfg...

CVE-2023-41562

CRITICAL CVSS 9.8 Aug 30, 2023

This vulnerability allows remote attackers to execute arbitrary code on affected Tenda routers via a stack overflow in the PowerSaveSet function. Attackers can exploit this by sending specially crafte...

CVE-2023-41552

CRITICAL CVSS 9.8 Aug 30, 2023

This CVE describes a critical stack overflow vulnerability in Tenda AC7 and AC9 routers that allows remote code execution. Attackers can exploit this by sending specially crafted requests to the vulne...

CVE-2023-41556

CRITICAL CVSS 9.8 Aug 30, 2023

This vulnerability allows remote attackers to execute arbitrary code on affected Tenda routers via a stack overflow in the SetIpMacBind function. Attackers can exploit this by sending specially crafte...

CVE-2023-38936

CRITICAL CVSS 9.8 Aug 7, 2023

This CVE describes a stack overflow vulnerability in multiple Tenda router models via the speed_dir parameter in the formSetSpeedWan function. Attackers can exploit this to execute arbitrary code or c...

CVE-2023-38930

CRITICAL CVSS 9.8 Aug 7, 2023

This vulnerability allows remote attackers to execute arbitrary code on affected Tenda routers via a stack overflow in the addWifiMacFilter function. Attackers can exploit this by sending specially cr...

CVE-2023-37717

CRITICAL CVSS 9.8 Jul 14, 2023

This vulnerability allows remote attackers to execute arbitrary code on affected Tenda routers via a stack overflow in the fromDhcpListClient function. Attackers can exploit this by sending specially ...

CVE-2025-11586

HIGH CVSS 8.8 Oct 10, 2025

This vulnerability in Tenda AC7 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the setNotUpgrade function. Attackers can exploit this without authentica...

CVE-2025-11528

HIGH CVSS 8.8 Oct 9, 2025

This vulnerability in Tenda AC7 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the saveAutoQos function. Attackers can exploit this without authenticati...

CVE-2025-11526

HIGH CVSS 8.8 Oct 9, 2025

This vulnerability in Tenda AC7 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the WifiMacFilterSet function. It affects users of Tenda AC7 firmware ver...

CVE-2025-11524

HIGH CVSS 8.8 Oct 9, 2025

A stack-based buffer overflow vulnerability in Tenda AC7 routers allows remote attackers to execute arbitrary code by manipulating the ddnsEn parameter in the SetDDNSCfg endpoint. This affects Tenda A...

CVE-2025-9023

HIGH CVSS 8.8 Aug 15, 2025

A buffer overflow vulnerability in Tenda AC7 and AC18 routers allows remote attackers to execute arbitrary code by manipulating the Time parameter in the formSetSchedLed function. This affects routers...

CVE-2025-5862

HIGH CVSS 8.8 Jun 9, 2025

A critical buffer overflow vulnerability in Tenda AC7 routers allows remote attackers to execute arbitrary code by manipulating the PPTP user list function. This affects Tenda AC7 routers running firm...

CVE-2025-4810

HIGH CVSS 8.8 May 16, 2025

A critical stack-based buffer overflow vulnerability in Tenda AC7 routers allows remote attackers to execute arbitrary code by manipulating the reboot_time parameter in the formSetRebootTimer function...

CVE-2025-4809

HIGH CVSS 8.8 May 16, 2025

A critical stack-based buffer overflow vulnerability in Tenda AC7 routers allows remote attackers to execute arbitrary code by manipulating the deviceList parameter in the fromSafeSetMacFilter functio...

CVE-2025-1851

HIGH CVSS 8.8 Mar 3, 2025

A critical stack-based buffer overflow vulnerability in Tenda AC7 routers allows remote attackers to execute arbitrary code by manipulating the firewallEn parameter. This affects all Tenda AC7 routers...

CVE-2024-48825

HIGH CVSS 8.8 Oct 28, 2024

This vulnerability allows remote attackers to execute arbitrary commands on Tenda AC7 routers without authentication. Attackers can inject malicious commands through the ate_ifconfig_set function, pot...

CVE-2024-32281

HIGH CVSS 8.8 Apr 17, 2024

Tenda AC7V1.0 routers running firmware version 15.03.06.44 contain a command injection vulnerability in the formexeCommand function via the cmdinput parameter. This allows authenticated attackers to e...

CVE-2024-2902

HIGH CVSS 8.8 Mar 26, 2024

This is a critical stack-based buffer overflow vulnerability in Tenda AC7 routers that allows remote attackers to execute arbitrary code by manipulating the shareSpeed parameter. It affects Tenda AC7 ...

CVE-2024-2900

HIGH CVSS 8.8 Mar 26, 2024

This critical vulnerability in Tenda AC7 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the saveParentControlInfo function. Attackers can exploit this w...

CVE-2024-2898

HIGH CVSS 8.8 Mar 26, 2024

This critical vulnerability in Tenda AC7 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the fromSetRouteStatic function. Attackers can exploit this with...

CVE-2024-2895

HIGH CVSS 8.8 Mar 26, 2024

This critical vulnerability in Tenda AC7 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the WPS configuration function. Attackers can exploit this witho...

CVE-2024-2893

HIGH CVSS 8.8 Mar 26, 2024

This critical vulnerability in Tenda AC7 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the device name setting function. Attackers can exploit this wit...

CVE-2024-2891

HIGH CVSS 8.8 Mar 26, 2024

This critical vulnerability in Tenda AC7 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the PPPOE password handling function. Attackers can exploit this...

CVE-2025-11523

MEDIUM CVSS 6.3 Oct 9, 2025

This vulnerability in Tenda AC7 routers allows remote attackers to execute arbitrary commands through command injection in the lanIp parameter of the AdvSetLanip endpoint. Attackers can potentially ta...

CVE-2024-10280

MEDIUM CVSS 6.5 Oct 23, 2024

A null pointer dereference vulnerability in Tenda routers allows remote attackers to cause denial of service by manipulating the Content-Length argument in the websReadEvent function. This affects mul...