S4E just found a low-severity finding from [ai] web application external link detection scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-31755 Scanner

CVE-2021-31755 scanner - Remote Code Execution (RCE) vulnerability in Tenda AC11

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.6k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2021-31755
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows attackers to execute arbitrary code on the system via a crafted post request.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Tenda AC11 is a popular wireless router designed for households and small businesses. It provides excellent connectivity and a high-speed internet browsing experience. It comes with professional features such as easy setup, parental controls, and advanced security options that provide users with a high-speed and secure network experience.

Recently, CVE-2021-31755 vulnerability was detected in Tenda AC11 firmware through 02.03.01.104_CN. This vulnerability exists in /goform/setmac functionality, and it allows attackers to execute arbitrary code on the system via a crafted post request. The stack buffer overflow vulnerability in Tenda AC11 is a critical security issue that needs to be addressed as soon as possible.

When exploited, the CVE-2021-31755 vulnerability can lead to severe consequences. An attacker can gain full control of the affected device, access sensitive information such as passwords, and perform malicious activities such as data theft, botnet attacks, and ransomware. The vulnerability can also result in the device becoming part of a large-scale attack, compromising not only its own security, but that of other devices on the network as well.

Thanks to the pro features of s4e.io platform, it is now easy and quick to learn about vulnerabilities in digital assets. The platform offers advanced scanning tools that can detect and report vulnerabilities in real-time, allowing businesses and individuals to take timely action. In addition, it provides comprehensive analytics and reporting that enable users to gain insight into their network's overall security posture and identify areas that need improvement. By using s4e.io, businesses and individuals can rest assured that their digital assets are safe and secure.

REFERENCES

Solution Advice

To protect against the vulnerability, several precautions can be taken, including:

  • Update Tenda AC11 firmware to the latest version to patch the vulnerability.
  • Disable remote management to prevent unauthorized access to the device.
  • Restrict access to the router by only allowing trusted devices and users to connect to the network.
  • Implement strong passwords and enable two-factor authentication to minimize the likelihood of unauthorized access.
  • Regularly monitor the device for any unusual activity or changes in configuration settings.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.