ZeroHour

CVE-2021-31755

KEV PoC large

Unauthenticated Stack Overflow RCE in Tenda AC11 Router via /goform/setmac

CISA: Tenda AC11 Router Stack Buffer Overflow Vulnerability

CVSS 3.1
9.8 critical
EPSS
87%p100
Published
()
KEV added
AI analysis

Tenda AC11 routers running firmware through 02.03.01.104_CN contain a stack buffer overflow (CWE-787 out-of-bounds write) in the /goform/setmac web endpoint. An unauthenticated attacker can trigger it with a crafted HTTP POST request, overwriting stack memory and executing arbitrary code on the device. Successful exploitation yields full control of the router, enabling traffic interception, lateral movement into the attached home or small-office network, or use in botnets. All AC11 units on affected CN firmware are in scope; no other Tenda products are named in this advisory. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), carries a very high EPSS score of 86.9%, and public proof-of-concept exploit material is available on GitHub.

What to do: Upgrade AC11 firmware to a release newer than 02.03.01.104_CN per Tenda's instructions (no specific fixed version is provided in this data), as required by the CISA KEV catalog. Until patched, disable or restrict WAN-facing HTTP management and monitor for unexpected POST requests to /goform/setmac. Review whether the router is reachable from the internet, since unauthenticated network access is all an attacker needs.

Affected
Tenda AC11 router firmwarethrough 02.03.01.104_CN (CN firmware builds up to and including this version)
Estimated exposure
largeplausibly on the order of 100,000+ consumer deployments, with tens of thousands directly internet-exposed (estimate) — Tenda is a high-volume consumer router brand and the AC11 is one of its widely sold budget home models, which typically translates to hundreds of thousands of units sold while public internet scans generally show only tens of thousands…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows attackers to execute arbitrary code on the system via a crafted post request.

CISA Known Exploited Vulnerability
Affected
Tenda AC11 Router
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
tenda
Products
ac11 firmware
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news