CVE-2026-19789

8.8

Tenda · AC1206

The Tenda AC1206 router is vulnerable to a stack-based buffer overflow, allowing memory corruption via specifically crafted input.

Executive summary

A stack-based buffer overflow in Tenda AC1206 routers allows authenticated attackers to execute arbitrary code or cause system crashes.

Vulnerability

The device is susceptible to a stack-based buffer overflow (CWE-121) and memory corruption (CWE-119). These flaws are reachable by an authenticated user with low privileges (PR:L) over the network.

Business impact

Successful exploitation of this vulnerability could lead to a complete compromise of the affected router, resulting in unauthorized access to the local network or denial of service. With a CVSS score of 8.8, this vulnerability represents a high risk to organizational infrastructure, as attackers could intercept traffic or pivot into internal systems.

Remediation

Immediate Action: Restrict access to the management interface to trusted administrative IP addresses only until a vendor-supplied patch is installed.

Proactive Monitoring: Inspect system logs for unexpected reboots or crashes that may indicate memory corruption attempts.

Compensating Controls: Utilize an internal firewall or network segmentation to isolate the management interface from non-administrative network segments.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS score and the potential for full device control, administrators should prioritize isolating affected Tenda AC1206 units. Monitor official Tenda support channels for firmware updates and apply them as soon as they become available to remediate the underlying memory corruption risk.

More Tenda CVEs