Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior contain an improper output encoding vulnerability in the web management interface. User-supplied input is reflected in HTTP responses without adequate escaping, allowing injection of arbitrary HTML or JavaScript in a victim’s browser context.
Metrics
Affected Vendors & Products
References
History
Tue, 03 Feb 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 03 Feb 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior contain an improper output encoding vulnerability in the web management interface. User-supplied input is reflected in HTTP responses without adequate escaping, allowing injection of arbitrary HTML or JavaScript in a victim’s browser context. | |
| Title | Tenda AC7 Reflected XSS via Web Interface Output Encoding | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-03T19:49:54.369Z
Reserved: 2026-01-22T20:23:19.802Z
Link: CVE-2026-24426
Updated: 2026-02-03T19:49:51.644Z
Status : Received
Published: 2026-02-03T19:16:16.390
Modified: 2026-02-03T19:16:16.390
Link: CVE-2026-24426
No data.
OpenCVE Enrichment
No data.