CVE-2026-1638

A security flaw has been discovered in Tenda AC21 1.1.1.1/1.dmzip/16.03.08.16. The impacted element is the function mDMZSetCfg of the file /goform/mDMZSetCfg. The manipulation of the argument dmzIp results in command injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
References
Link Resource
https://github.com/LX-LX88/cve/issues/26 Broken Link
https://vuldb.com/?ctiid.343417 Permissions Required VDB Entry
https://vuldb.com/?id.343417 Third Party Advisory VDB Entry
https://vuldb.com/?submit.740871 Third Party Advisory VDB Entry
https://www.tenda.com.cn/ Product
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tenda:ac21_firmware:16.03.08.16:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac21:-:*:*:*:*:*:*:*

History

09 Mar 2026, 17:35

Type Values Removed Values Added
First Time Tenda
Tenda ac21
Tenda ac21 Firmware
References () https://github.com/LX-LX88/cve/issues/26 - () https://github.com/LX-LX88/cve/issues/26 - Broken Link
References () https://vuldb.com/?ctiid.343417 - () https://vuldb.com/?ctiid.343417 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.343417 - () https://vuldb.com/?id.343417 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.740871 - () https://vuldb.com/?submit.740871 - Third Party Advisory, VDB Entry
References () https://www.tenda.com.cn/ - () https://www.tenda.com.cn/ - Product
CPE cpe:2.3:o:tenda:ac21_firmware:16.03.08.16:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac21:-:*:*:*:*:*:*:*

04 Feb 2026, 16:34

Type Values Removed Values Added
Summary
  • (es) Se ha descubierto una falla de seguridad en Tenda AC21 1.1.1.1/1.dmzip/16.03.08.16. El elemento afectado es la función mDMZSetCfg del archivo /goform/mDMZSetCfg. La manipulación del argumento dmzIp resulta en inyección de comandos. El ataque puede ser ejecutado remotamente. El exploit ha sido publicado y puede ser usado para ataques.

30 Jan 2026, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-30 00:15

Updated : 2026-03-09 17:35


NVD link : CVE-2026-1638

Mitre link : CVE-2026-1638

CVE.ORG link : CVE-2026-1638


JSON object : View

Products Affected

tenda

  • ac21
  • ac21_firmware
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')