CVE Tools

AC21 Firmware

29 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for AC21 Firmware, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.

AC21 Firmware CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
AC21 Firmware CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-081
2025-092
2025-100
2025-118
2025-120
2026-012
2026-022
2026-031
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 29 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical13%
  • High2069%
  • Medium828%

Latest CVEs

The 15 most recently published vulnerabilities affecting AC21 Firmware.

  1. CVE-2026-4565Tenda AC21 SetNetControlList formSetQosBand buffer overflow8.8
  2. CVE-2026-2148Tenda AC21 Web Management DownloadFlash information disclosure5.3
  3. CVE-2026-2147Tenda AC21 Web Management DownloadLog information disclosure5.3
  4. CVE-2026-1638Tenda AC21 mDMZSetCfg command injection6.3
  5. CVE-2026-1637Tenda AC21 AdvSetMacMtuWan fromAdvSetMacMtuWan stack-based overflow8.8
  6. CVE-2025-13446Tenda AC21 SetSysTimeCfg stack-based overflow8.8
  7. CVE-2025-13445Tenda AC21 SetIpMacBind stack-based overflow8.8
  8. CVE-2025-65221Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the list parameter of /goform/setPptpUserList.4.3
  9. CVE-2025-65223Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the urls parameter of /goform/saveParentControlInfo.4.3
  10. CVE-2025-65222Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the rebootTime parameter of /goform/SetSysAutoRebbotCfg.4.3
  11. CVE-2025-65226Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the deviceId parameter in /goform/saveParentControlInfo.4.3
  12. CVE-2025-65220Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow in: /goform/SetVirtualServerCfg via the list parameter.4.3
  13. CVE-2025-12611Tenda AC21 SetPptpServerCfg formSetPPTPServer buffer overflow8.8
  14. CVE-2025-11091Tenda AC21 SetStaticRouteCfg sscanf buffer overflow8.8
  15. CVE-2025-10838Tenda AC21 WifiExtraSet sub_45BB10 buffer overflow8.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store