CVE-2026-24426: Tenda AC7 Reflected XSS via Web Interface Output Encoding
Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior contain an improper output encoding vulnerability in the web management interface. User-supplied input is reflected in HTTP responses without adequate escaping, allowing injection of arbitrary HTML or JavaScript in a victim’s browser context.
Security readout for executives and security teams
Plain-English summary
This is a reflected cross-site scripting issue in the Tenda AC7 router management interface. A crafted request could cause a user’s browser to run attacker-controlled script in that interface. The sources rate it medium severity and require user interaction; they do not report active exploitation.
Executive priority
Treat this as a moderate-priority router management risk. It is not reported as actively exploited, but affected edge devices should be inventoried and management access tightened while waiting for or applying vendor guidance.
Technical view
CVE-2026-24426 is CWE-79 improper output encoding in Tenda AC7 firmware V03.03.03.01_cn and prior. User-supplied input is reflected in HTTP responses without adequate escaping, enabling HTML or JavaScript execution in the victim browser context. CVSS v4.0 score is 5.1, with network attack vector, low complexity, no privileges, and active user interaction.
Likely exposure
Exposure is likely limited to organizations or homes using Tenda AC7 devices on affected firmware, particularly where users can reach the web management interface. Risk increases if administration is exposed beyond trusted networks.
Exploitation context
The source bundle does not cite public exploitation or CISA KEV listing. Exploitation requires user interaction, such as a victim loading attacker-influenced content, and would affect the browser session context for the router’s management interface.
Researcher notes
The provided affected-version metadata is imperfect: the description names V03.03.03.01_cn and prior, while the structured affected entry lists version 0 with default unaffected. Do not broaden scope beyond Tenda AC7 without further vendor evidence.
Mitigation direction
Inventory Tenda AC7 devices and record firmware versions.
Check Tenda and advisory sources for fixed firmware or vendor guidance.
Restrict management interface access to trusted administrative networks only.
Disable remote administration if it is not required.
Educate administrators not to open unsolicited router-management links.
Validation and detection
Confirm whether any Tenda AC7 devices run V03.03.03.01_cn or earlier.
Verify the management interface is not reachable from untrusted networks.
Review vendor and VulnCheck advisory pages for current remediation status.
Use only authorized, non-destructive testing to assess output encoding behavior.
Check access logs for unusual management-interface requests.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-79: User-session and phishing behavior lookup
Client-side and session-facing weaknesses should be reviewed alongside initial-access and user-execution behaviors. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-79 · source CWE mapping
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.