Tenda
Tenda Ac1206: vulnerabilities and CVEs
Tenda Ac1206 has 6 published vulnerabilities, 5 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.
CVEs6
Last 12 months5
Critical2
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-82694 | Critical (9.3) | 1.4% | — | Aug 31, 2026 | A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the function R7WebsSecurityHandler of the file /goform/ate of the component Web UI. The manipulation leads to missing authentication. The… |
| CVE-2026-82693 | Critical (9.3) | 1.4% | — | Aug 31, 2026 | A vulnerability was determined in Tenda AC1206 15.03.06.23. This vulnerability affects the function TendaTelnet of the file /goform/telnet of the component Web UI. Executing a manipulation can lead to missing… |
| CVE-2026-19789 | High (7.4) | 0.85% | — | Aug 14, 2026 | A vulnerability was determined in Tenda AC1206 15.03.06.23_multi_TD01. This vulnerability affects the function set_wl_guest_iplist of the file /goform/WifiGuestSet of the component httpd web management interface. This… |
| CVE-2026-19788 | High (7.4) | 0.85% | — | Aug 14, 2026 | A vulnerability was found in Tenda AC1206 15.03.06.23_multi_TD01. This affects the function set_device_name of the file /goform/SetOnlineDevName of the component httpd web management interface. The manipulation of the… |
| CVE-2026-36789 | High (7.5) | 0.55% | — | Jun 8, 2026 | Shenzhen Tenda Technology Co., Ltd Tenda AC1206 v15.03.06.23 was discovered to contain multiple stack overflows in the fromGstDhcpSetSer function via the username and password parameters. These vulnerabilities allow… |
| CVE-2024-53621 | High (7.5) | 0.42% | — | Jun 30, 2025 | A buffer overflow in the formSetCfm() function of Tenda AC1206 1200M 11ac US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 allows attackers to cause a Denial of Service (DoS) via a crafted POST request. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.