


Perceptive Security
SOC/SIEM Consultancy

A security flaw has been discovered in Tenda AC15 up to 15.13.07.13. Affected by this issue is some unknown functionality of the file /goform/TextEditingConvers…
Published:
1 March 2026 at 23:00:00
Alert date:
2 March 2026 at 01:01:02
Source:
nvd.nist.gov
Network Infrastructure, Mobile & IoT
A critical security vulnerability has been discovered in Tenda AC15 routers up to version 15.13.07.13. The flaw exists in the /goform/TextEditingConversion file where manipulation of the wpapsk_crypto2_4g argument leads to a stack-based buffer overflow. This vulnerability can be exploited remotely by attackers. The exploit code has been publicly released, making this a high-priority security concern. Organizations using affected Tenda AC15 devices should prioritize patching or mitigation measures immediately.
Technical details
Mitigation steps:
Affected products:
Tenda AC15
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-3400
https://vuldb.com/?ctiid.348295
https://vuldb.com/?id.348295
https://vuldb.com/?submit.760109
https://www.tenda.com.cn/
https://www.yuque.com/ba1ma0-an29k/nnxoap/tzg68iadbmqx6esm?singleDoc#
Related CVE's:
Related threat actors:
IOC's:
/goform/TextEditingConversion, wpapsk_crypto2_4g
This article was created with the assistance of AI technology by Perceptive.
