Description
A buffer overflow vulnerability was discovered in goform/formSetMacFilterCfg in Tenda AC15V1.0 V15.03.05.18_multi.
Published: 2026-03-03
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

A buffer overflow exists in the goform/formSetMacFilterCfg handler of the Tenda AC15 V15.03.05.18_multi firmware. This flaw allows an attacker who can send a specially crafted request to the router’s configuration interface to overwrite memory on the device. If exploited, the attacker could gain arbitrary code execution, compromising the integrity and confidentiality of the router and potentially the devices connected to it.

Affected Systems

The vulnerability affects the Tenda AC15 router model, specifically firmware version 15.03.05.18_multi. System administrators managing devices listed under the hardware identifier ac15 v1.0 should verify that they are running this firmware or a newer patched release.

Risk and Exploitability

The CVSS score of 9.8 indicates critical severity, while the EPSS score of less than 1% suggests low available exploitation probability at the time of analysis. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, so no confirmed exploits are publicly known. Nonetheless, the attack vector is inferred to be remote via the router’s HTTP management interface; an attacker could construct a request without authentication if the interface is exposed to the public network or accessed by an untrusted internal user. Given its high impact, the potential for remote code execution remains a top concern for any organization still running the affected firmware.

Generated by OpenCVE AI on April 16, 2026 at 14:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the router firmware to the latest version released by Tenda that addresses the buffer overflow issue.
  • If an immediate firmware update is not possible, restrict access to the management interface to trusted IP addresses or VPN connections to reduce exposure to unauthenticated users.
  • Implement network segmentation so that the router’s administrative network is isolated from devices that could be compromised if the router is exploited.
  • Monitor the router’s logs for anomalous configuration requests or repeated failed packets that could indicate an attempted exploitation.

Generated by OpenCVE AI on April 16, 2026 at 14:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 16 Apr 2026 14:30:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in Tenda AC15 Configuration API Enabling Potential Remote Code Execution

Thu, 05 Mar 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Tenda ac15 Firmware
CPEs cpe:2.3:h:tenda:ac15:1.0:*:*:*:*:*:*:*
cpe:2.3:o:tenda:ac15_firmware:15.03.05.18_multi:*:*:*:*:*:*:*
Vendors & Products Tenda ac15 Firmware

Thu, 05 Mar 2026 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 04 Mar 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Tenda
Tenda ac15
Vendors & Products Tenda
Tenda ac15

Tue, 03 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
Description A buffer overflow vulnerability was discovered in goform/formSetMacFilterCfg in Tenda AC15V1.0 V15.03.05.18_multi.
References

Subscriptions

Tenda Ac15 Ac15 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-03-05T16:25:56.029Z

Reserved: 2026-01-21T00:00:00.000Z

Link: CVE-2026-24103

cve-icon Vulnrichment

Updated: 2026-03-05T16:25:28.005Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-03T15:16:18.787

Modified: 2026-03-05T21:43:07.170

Link: CVE-2026-24103

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T14:15:28Z

Weaknesses