CVE-2026-1637Disclosure(tenda / ac21)

LOWCVSS 7.4 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was identified in Tenda AC21 16.03.08.16. The affected element is the function fromAdvSetMacMtuWan of the file /goform/AdvSetMacMtuWan. The manipulation leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ac21
  • ac21_firmware

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 2 mentions (2026-01-29); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
ac21ac21_firmware

2 versions affected across 2 products

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-01-29: 2Mentions · 2026-01-30: 2Technical Details · 2026-01-29: 1Technical Details · 2026-01-30: 201-2901-30
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Full discourse4 posts
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-1637: HIGH] Critical vulnerability found in Tenda AC21 16.03.08.16 allows remote attackers to perform a stack-based buffer overflow through /goform/AdvSetMacMtuWan function, with a publicly available...#cve,CVE-2026-1637,#cybersecurity https://cvefind.com/CVE-2026-1637

    Post summary

    The post announces a critical stack-based buffer overflow vulnerability (CVE‑2026‑1637) in Tenda AC21 firmware, providing technical details but no evidence of exploitation, patches, or PoC.

    10000101
    584 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1637 Tenda AC21 Remote Stack Overflow Vulnerability in Network Configuration Function https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1637

    Post summary

    The text announces CVE‑2026‑1637 as a remote stack overflow in the Tenda AC21 network configuration function, with reference to an external vulnerability detail page.

    0000077
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1637 A vulnerability was identified in Tenda AC21 16.03.08.16. The affected element is the function fromAdvSetMacMtuWan of the file /goform/AdvSetMacMtuWan. The manipulation… https://www.cve.org/CVERecord?id=CVE-2026-1637

    Post summary

    A new vulnerability (CVE-2026-1637) affecting Tenda AC21 routers has been identified; the flaw involves the function fromAdvSetMacMtuWan in the /goform/AdvSetMacMtuWan endpoint.

    00000392
    56.5K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    There is a new vulnerability with elevated criticality in Tenda AC21 (CVE-2026-1637) https://vuldb.com/?id.343416

    Post summary

    A new critical vulnerability (CVE-2026-1637) in the Tenda AC21 router has been disclosed with an elevated criticality rating. Detailed information can be found via the provided vulnerability database link.

    0000085
    2.1K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendaac21---
OStendaac21_firmware16.03.08.16--

Explore more