---
id: CVE-2021-31627
title: >-
  Buffer Overflow vulnerability in Tenda AC9 V1.0 through V15.03.05.19(6318),
  and AC9 V3.0 V15.03.06.42_multi, allows attackers to execute arbitrary code
  via the index parameter.
summary: >-
  Buffer Overflow vulnerability in Tenda AC9 V1.0 through V15.03.05.19(6318),
  and AC9 V3.0 V15.03.06.42_multi, allows attackers to execute arbitrary code
  via the index parameter.
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-120
vendor: tendacn
product: ac9_firmware
affected:
  - ac9_firmware <= 15.03.06.42_multi
  - ac9_firmware <= 15.03.05.19\(6318\)
published: '2021-10-29'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-31627'
references:
  - url: 'https://github.com/Lyc-heng/routers/blob/main/routers/stack3.md'
    label: cve@mitre.org
  - url: 'http://tenda.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/Lyc-heng/routers/blob/main/routers/stack3.md'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.01144
epssPercentile: 0.65388
ingestedAt: '2026-07-06T01:08:17.045Z'
---

## Overview

Buffer Overflow vulnerability in Tenda AC9 V1.0 through V15.03.05.19(6318), and AC9 V3.0 V15.03.06.42_multi, allows attackers to execute arbitrary code via the index parameter.

## Affected

- `ac9_firmware <= 15.03.06.42_multi`
- `ac9_firmware <= 15.03.05.19\(6318\)`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
