An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows attackers to execute arbitrary code on the system via a crafted post request.
Is CVE-2021-31755 exploited?
Listed in the CISA KEV catalog on 2021-11-03.
Federal remediation due 2021-11-17.
Past that date by 1732 days.
EPSS puts exploitation in the next 30 days at 86%.
Public exploit code: none found in monitored sources.