CVE-2026-1610
8.1Tenda · AX12 Pro V2
Tenda AX12 Pro V2 devices contain hard-coded credentials within the Telnet Service, allowing remote attackers to potentially gain unauthorized system access.
Executive summary
The Tenda AX12 Pro V2 router is susceptible to unauthorized access due to hard-coded credentials in the Telnet service, posing a critical risk to network security.
Vulnerability
The device uses hard-coded credentials within its Telnet service implementation. This flaw allows an unauthenticated remote attacker to potentially bypass standard authentication mechanisms if they can reach the service.
Business impact
Successful exploitation of this vulnerability grants an attacker full control over the affected network device. Given the CVSS score of 8.1, the business impact is severe, as it enables unauthorized access to internal network traffic, potential interception of sensitive data, and the ability to pivot into the local area network. This compromise could lead to significant operational disruption and a breach of organizational data privacy.
Remediation
Immediate Action: Disable the Telnet service on the Tenda AX12 Pro V2 immediately and restrict management access to trusted interfaces only.
Proactive Monitoring: Review device logs for unauthorized login attempts or unexpected Telnet session activity originating from unknown IP addresses.
Compensating Controls: Implement network segmentation to isolate the affected router from the primary business network and utilize firewall rules to block external access to the Telnet port.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists and is attributed to the research documentation provided in the vulnerability record.
Analyst recommendation
Given the severity of hard-coded credentials and the availability of a public proof-of-concept, users must prioritize securing the management interface of their Tenda devices. Administrators should disable Telnet immediately and await further guidance from the vendor regarding a firmware update to remove the hard-coded credentials.
More Tenda CVEs
Sources
Originally found and disclosed by hhsw34 (VulDB User), per the CVE Program record.
- VDB-343378 | Tenda AX12 Pro V2 Telnet Service hard-coded credentials Vulnerability database entry
- VDB-343378 | CTI Indicators (IOB, IOC, TTP)
- Submit #740766 | Tenda AX12 pro V2 V16.03.49.24_cn Hard-coded Credentials Third-party advisory
- Exploit / PoC
- tenda.com.cn