Skip to main content
Vulnerability Database/CVE-2026-104611

CVE-2026-104611: Tenda AC9 Buffer Overflow Vulnerability

CVE-2026-104611 is a stack-based buffer overflow in Tenda AC9 router firmware that allows remote attackers to exploit the POST request handler. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-104611 Overview

CVE-2026-104611 is a stack-based buffer overflow vulnerability affecting Tenda AC9 routers running firmware version 15.03.02.13. The flaw resides in the /goform/fast_setting_internet_set endpoint handled by the device's POST request handler. An attacker can trigger the overflow by manipulating the netWanType argument submitted in an HTTP POST request. The vulnerability is remotely exploitable over the network, and a public exploit has been disclosed, increasing the likelihood of opportunistic targeting. The weakness is classified under CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer.

Critical Impact

Successful exploitation can corrupt the router's memory, enabling denial of service or arbitrary code execution on the affected device.

Affected Products

  • Tenda AC9 router, firmware 15.03.02.13
  • /goform/fast_setting_internet_set POST request handler
  • Devices exposing the web management interface to untrusted networks

Discovery Timeline

  • 2026-10-02 - CVE-2026-104611 published to the National Vulnerability Database (NVD)
  • 2026-10-02 - Last updated in the NVD database

Technical Details for CVE-2026-104611

Vulnerability Analysis

The vulnerability affects the web management interface of the Tenda AC9 router. When processing a POST request to /goform/fast_setting_internet_set, the handler reads the attacker-controlled netWanType parameter without validating its length. The value is then copied into a fixed-size stack buffer, overrunning adjacent stack memory. This condition allows an attacker to overwrite return addresses or saved registers and influence control flow on the embedded MIPS-based platform. Public documentation describing the issue is available in the GitHub CVE write-up and the VulDB entry for CVE-2026-104611.

Root Cause

The root cause is the absence of bounds checking on the netWanType POST parameter before it is written to a stack-allocated buffer. The handler relies on unsafe string copy operations typical of embedded goform CGI handlers. Because the buffer is sized for expected short identifier values, any oversized input corrupts the stack frame.

Attack Vector

Exploitation requires network reachability to the router's HTTP management interface and valid administrative access to submit the crafted POST request. An attacker sends a POST body containing an oversized netWanType value to /goform/fast_setting_internet_set. The device processes the request, triggers the overflow, and either crashes or executes attacker-supplied shellcode within the HTTP server process. A public proof-of-concept is referenced on VulDB, lowering the barrier to weaponization.

Detection Methods for CVE-2026-104611

Indicators of Compromise

  • Unexpected HTTP POST requests to /goform/fast_setting_internet_set from external or unmanaged sources
  • Abnormally long values submitted in the netWanType POST parameter
  • Repeated reboots, crashes, or watchdog resets of Tenda AC9 devices
  • New or unexplained configuration changes on router WAN interfaces

Detection Strategies

  • Deploy network intrusion detection signatures that inspect POST bodies to /goform/fast_setting_internet_set and flag oversized netWanType values
  • Monitor router syslog output for HTTP server crashes, segmentation faults, or restart loops
  • Correlate inbound HTTP traffic to router management ports with authentication failure patterns to identify brute-force attempts preceding exploitation

Monitoring Recommendations

  • Capture and retain HTTP management traffic to IoT and SOHO router subnets for forensic review
  • Alert on administrative sessions originating from WAN interfaces or non-corporate IP ranges
  • Track firmware versions across managed network devices to identify assets still running 15.03.02.13

How to Mitigate CVE-2026-104611

Immediate Actions Required

  • Restrict access to the router's web management interface to trusted internal networks only and disable WAN-side administration
  • Rotate administrative credentials on all Tenda AC9 devices to limit abuse of the required privileges
  • Isolate affected routers in network segments that do not host sensitive workloads until a patch is applied
  • Review router logs for signs of exploitation attempts against the /goform/fast_setting_internet_set endpoint

Patch Information

No vendor advisory or firmware update addressing CVE-2026-104611 has been published in the referenced sources at the time of writing. Consult the Tenda official website for firmware updates and monitor the VulDB vulnerability entry for remediation guidance.

Workarounds

  • Disable remote web administration and limit the management interface to a dedicated management VLAN
  • Place the router behind an upstream firewall that filters inbound HTTP traffic to the device
  • Replace unsupported or end-of-life Tenda AC9 units with devices that receive active security maintenance
bash
# Example firewall rule to block external access to the router management interface
iptables -A INPUT -p tcp --dport 80 ! -s 192.168.0.0/24 -j DROP
iptables -A INPUT -p tcp --dport 443 ! -s 192.168.0.0/24 -j DROP

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.