A remotely exploitable stack-based buffer overflow in Tenda AC9 firmware 15.03.02.13 has a public exploit and carries a CVSS 3.1 score of 9.1 (Critical).
What Is It
CVE-2026-104611 is a stack-based buffer overflow (CWE-121, CWE-119) in the Tenda AC9 router. The flaw sits in the POST Request Handler component, in an unspecified function of the /goform/fast_setting_internet_set endpoint. An attacker can trigger the overflow by manipulating the netWanType argument in a request to that endpoint.
VulDB, acting as the CNA, reported the issue. NVD published it on 2026-10-02, and its current status is "Deferred."
Why It Matters
The flaw can be attacked over the network. The CVSS 3.1 vector is AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H, which means:
- Attack vector: Network
- Attack complexity: Low
- Privileges required: High
- User interaction: None
- Scope: Changed
- Impact: High for confidentiality, integrity and availability
The CVSS 4.0 secondary score is 8.5 (High), with exploit maturity rated "Proof of Concept." The CVSS 2.0 score is 8.3 (High).
According to the CVE description, the exploit is public and may be used. A third-party write-up is linked in the references.
KEV status: CVE-2026-104611 is not in the supplied CISA KEV data. CISA has not confirmed active exploitation in the wild, so there is no KEV remediation deadline.
Because the attack needs high privileges, an attacker would most likely need authenticated access to the router's management interface. Even so, the impact ratings and the public exploit make this flaw worth prioritizing on exposed or shared-access devices.
What's Vulnerable
- Vendor: Tenda
- Product: AC9
- Affected version: Firmware 15.03.02.13
- Component: POST Request Handler (
/goform/fast_setting_internet_set) - CPE:
cpe:2.3:o:tenda:ac9_firmware:*:*:*:*:*:*:*:*
The source data lists only version 15.03.02.13 as affected.
Patch Status
The supplied NVD and VulDB data does not mention a vendor patch, a fixed firmware version or a Tenda advisory. Since CVE-2026-104611 is not in KEV, there is no CISA-mandated required action.
Owners of affected AC9 units should check Tenda's site for firmware updates. Until a fix is confirmed, they should restrict access to the router's management interface.