LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-31755: Tenda AC11 Router Stack Buffer Overflow Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Nov 17, 2021
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-31755 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of Nov 17, 2021 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Tenda AC11 devices contain a stack buffer overflow vulnerability in /goform/setmac which allows attackers to execute code via a crafted post request.

CVE-2021-31755 is a stack buffer overflow in the Tenda AC11 router that can let an attacker run code by sending a crafted POST request to the /goform/setmac endpoint. For IT and security teams, this matters because a compromised edge router can expose the internal network, intercept traffic, or serve as a foothold for further intrusion.

Public detail is limited to the CISA description and the CWE classification; confirm exact impact, fixed builds, and exposure conditions against the vendor advisory before acting.

How it works

The weakness is CWE-787 (out-of-bounds write). On the Tenda AC11, the /goform/setmac handler does not adequately bound data from a crafted POST request before writing it to a stack buffer. An attacker who can reach that interface can overflow the buffer and potentially achieve code execution on the device.

No further exploit mechanics, authentication requirements, or preconditions are stated in the provided facts. Treat any internet-facing or poorly segmented management path as higher risk, and verify the precise attack surface in the vendor advisory.

Am I affected? How to find it in your systems

This issue affects Tenda AC11 routers. These devices commonly appear as small-office or home-office gateways, Wi-Fi access points, or branch routers.

If you cannot confirm the model or firmware, assume potential exposure until verified against the vendor advisory.

How to remediate

Patch first. Apply the updates provided by the vendor per their instructions, as required by CISA guidance for this CVE. Confirm the advisory lists the exact fixed firmware for the AC11 and install it through the supported upgrade path.

If you can't patch immediately

Reduce reachability and monitor until the vendor update can be applied.

These steps only lower risk; they do not replace the vendor patch.

If your data may have been exposed

Actively exploited router vulnerabilities can lead to network compromise and data exposure even when ransomware use is not documented for this CVE. If you suspect exploitation, isolate the device, preserve logs, rotate credentials that traversed the router, and review internal systems for lateral movement. You can run a free exposure scan of your email addresses against known breach data to see whether associated accounts appear in public breach corpora, then prioritize password resets and monitoring for those identities.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedTenda · AC11 Router
WeaknessCWE-787
Added to CISA KEVNov 3, 2021
Federal patch deadlineNov 17, 2021
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities