CVE-2026-19789
8.8Tenda · AC1206
The Tenda AC1206 router is vulnerable to a stack-based buffer overflow, allowing memory corruption via specifically crafted input.
Executive summary
A stack-based buffer overflow in Tenda AC1206 routers allows authenticated attackers to execute arbitrary code or cause system crashes.
Vulnerability
The device is susceptible to a stack-based buffer overflow (CWE-121) and memory corruption (CWE-119). These flaws are reachable by an authenticated user with low privileges (PR:L) over the network.
Business impact
Successful exploitation of this vulnerability could lead to a complete compromise of the affected router, resulting in unauthorized access to the local network or denial of service. With a CVSS score of 8.8, this vulnerability represents a high risk to organizational infrastructure, as attackers could intercept traffic or pivot into internal systems.
Remediation
Immediate Action: Restrict access to the management interface to trusted administrative IP addresses only until a vendor-supplied patch is installed.
Proactive Monitoring: Inspect system logs for unexpected reboots or crashes that may indicate memory corruption attempts.
Compensating Controls: Utilize an internal firewall or network segmentation to isolate the management interface from non-administrative network segments.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high CVSS score and the potential for full device control, administrators should prioritize isolating affected Tenda AC1206 units. Monitor official Tenda support channels for firmware updates and apply them as soon as they become available to remediate the underlying memory corruption risk.