Back to search
CVE-2026-24426
Published: Feb 3, 2026
Modified: May 25, 2026
PUBLISHED
Description
Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior contain an improper output encoding vulnerability in the web management interface. User-supplied input is reflected in HTTP responses without adequate escaping, allowing injection of arbitrary HTML or JavaScript in a victim’s browser context.
| Vendor | Product | Versions |
|---|---|---|
Shenzhen Tenda Technology Co., Ltd. | Tenda AC7 | affected 0 - <= 03.03.03.01_cn |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now