Back to search
CVE-2026-24434
Published: Feb 3, 2026
Modified: May 14, 2026
PUBLISHED
Description
Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior does not implement CSRF protections for administrative functions in the web management interface. The interface does not enforce anti-CSRF tokens or robust origin validation, which can allow an attacker to induce a logged-in administrator to perform unintended state-changing requests and modify router settings.
| Vendor | Product | Versions |
|---|---|---|
Shenzhen Tenda Technology Co., Ltd. | Tenda AC7 | affected 0 - <= 03.03.03.01_cn |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now