CVE-2026-19821

8.8

Tenda · AC12

The Tenda AC12 router is susceptible to a buffer overflow and memory corruption vulnerability, which can be triggered by an authenticated attacker.

Executive summary

An authenticated buffer overflow vulnerability in the Tenda AC12 router could allow an attacker to cause memory corruption, potentially leading to arbitrary code execution.

Vulnerability

The device is vulnerable to buffer overflow (CWE-120) and memory corruption (CWE-119) due to improper input handling. An attacker with authenticated access can exploit these flaws to crash the device or execute arbitrary code.

Business impact

With a CVSS score of 8.8, this vulnerability represents a severe threat to network infrastructure. Successful exploitation could lead to full device compromise, allowing the attacker to intercept traffic, pivot into the internal network, or cause persistent denial of service, which is particularly damaging for networking equipment.

Remediation

Immediate Action: Check the Tenda support website for the latest firmware release for the AC12 model and apply it immediately. If no update is available, consider isolating the device from the network.

Proactive Monitoring: Monitor the router for unexpected reboots or service instability, which may indicate attempted exploitation of the memory corruption flaw.

Compensating Controls: Disable administrative access from the WAN interface and restrict management access to a dedicated, secure management VLAN or local-only connections.

Exploitation status

Public Exploit Available: Yes, a proof-of-concept exists in a public GitHub repository (per enrichment.references).

Analyst recommendation

The presence of a public proof-of-concept significantly increases the risk of exploitation for this device. Users should prioritize updating the firmware and enforcing strict network access controls to mitigate the risk until a definitive patch is confirmed and applied.

More Tenda CVEs