← Vulnerability feed

Vulnerability record · CVE-2021-31755 · published 7 May 2021

CVE-2021-31755: Tenda AC11 router setmac stack buffer overflow

Tenda · Ac11 Firmware

Tenda AC11 devices running firmware through 02.03.01.104_CN contain a stack buffer overflow in the /goform/setmac handler. A crafted POST request can overwrite stack memory and lead to arbitrary code execution on the device. The flaw is remotely reachable without authentication, making it a serious risk for internet-exposed routers.

9.8 CVSS 3.1 Critical CISA KEV since 3 Nov 2021 EPSS 87% · top 0.3% CWE-787 · Out-of-bounds write
9.8CVSS 3.1 base score, v2 10.0
87%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows attackers to execute arbitrary code on the system via a crafted post request.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityRemote unauthenticated code execution on an internet-facing router, confirmed in CISA KEV with very high EPSS probability.

What it is

Tenda AC11 devices running firmware through 02.03.01.104_CN contain a stack buffer overflow in the /goform/setmac handler. A crafted POST request can overwrite stack memory and lead to arbitrary code execution on the device. The flaw is remotely reachable without authentication, making it a serious risk for internet-exposed routers.

Impact

An attacker can execute arbitrary code on the router with the privileges of the affected service, gaining full control of the device. That enables traffic interception, persistent implanting, or use of the router as a pivot into the local network.

Attack surface

The vulnerability is reached over the network through the /goform/setmac HTTP endpoint. The CVSS vector indicates no privileges and no user interaction are required, so any host that can reach the management interface can attempt exploitation.

Exploitation

CVE-2021-31755 is listed in CISA KEV with a required action deadline of 2021-11-17, and EPSS shows a 30-day probability of 0.869 (99.7th percentile). Public exploit references exist, though the linked GitHub repository is tagged as a broken link.

What to do

  • Apply the vendor firmware update for Tenda AC11 devices; if no fixed firmware is available, replace or retire the device.
  • Remove the router management interface from the public internet and restrict /goform access to trusted management networks.
  • Segment IoT and router management traffic from production and user networks to limit lateral movement after compromise.
  • Monitor vendor advisories and CISA KEV for updated guidance, and verify firmware version on all AC11 units.
  • Where feasible, disable remote administration and change default administrative credentials.

Detection

  • Inspect HTTP logs and packet captures for POST requests to /goform/setmac with unusually long or malformed parameters.
  • Alert on router management interface access from unexpected external or non-management source addresses.
  • Monitor for unexpected outbound connections, new listening services, or configuration changes on AC11 devices.
  • Compare running firmware against the known affected version 02.03.01.104_CN and flag unpatched units.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-31755 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Tenda AC11 Router Stack Buffer Overflow Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/Yu3H0/IoT_CVE/tree/main/Tenda/CVE_3 Broken LinkExploitIssue TrackingThird Party Advisory
https://github.com/Yu3H0/IoT_CVE/tree/main/Tenda/CVE_3 Broken LinkExploitIssue TrackingThird Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-31755 US Government Resource

Track CVE-2021-31755 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-46262Tenda ac11 firmware out-of-bounds write vulnerabilityTenda AC Series Router AC11_V02.03.01.104_CN was discovered to contain a stack buffer overflow in the PPPoE module. This vulnerability allows attacke…EPSS 1.7%9.8CVE-2021-46263Tenda ac11 firmware out-of-bounds write vulnerabilityTenda AC Series Router AC11_V02.03.01.104_CN was discovered to contain a stack buffer overflow in the wifiTime module. This vulnerability allows atta…EPSS 1.7%9.8CVE-2021-46264Tenda ac11 firmware out-of-bounds write vulnerabilityTenda AC Series Router AC11_V02.03.01.104_CN was discovered to contain a stack buffer overflow in the onlineList module. This vulnerability allows at…EPSS 1.7%9.8CVE-2021-46265Tenda ac11 firmware out-of-bounds write vulnerabilityTenda AC Series Router AC11_V02.03.01.104_CN was discovered to contain a stack buffer overflow in the wanBasicCfg module. This vulnerability allows a…EPSS 1.7%9.8CVE-2021-46321Tenda ac11 firmware out-of-bounds write vulnerabilityTenda AC Series Router AC11_V02.03.01.104_CN was discovered to contain a stack buffer overflow in the wifiBasicCfg module. This vulnerability allows …EPSS 1.7%9.8CVE-2021-31756Tenda ac11 firmware out-of-bounds write vulnerabilityAn issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /gofrom/setwanType allo…EPSS 2.9%9.8CVE-2021-31757Tenda ac11 firmware out-of-bounds write vulnerabilityAn issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setVLAN allows …EPSS 3.3%9.8CVE-2021-31758Tenda ac11 firmware out-of-bounds write vulnerabilityAn issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setportList all…EPSS 6.6%

Source: NIST National Vulnerability Database (record CVE-2021-31755), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.