CVE-2026-82693
—Missing Authentication in Tenda AC1206 Web UI Telnet Endpoint
CVE-2026-82693 is a missing-authentication flaw (CWE-306/CWE-287) in the TendaTelnet function of the file /goform/telnet, part of the Web UI of the Tenda AC1206 router running firmware 15.03.06.23. An unauthenticated remote attacker can trigger the flaw by sending a manipulated request to this endpoint, which bypasses authentication on the Telnet component. With a CVSS 4.0 base score of 9.3 and high ratings for confidentiality, integrity, and availability (including on subsequent systems), an attacker who reaches this endpoint could gain substantial, potentially full, control of the device, though the advisory does not detail the exact post-access capabilities. Operators of Tenda AC1206 routers on the affected firmware are exposed, particularly devices whose Web UI is reachable from the internet or untrusted networks. Per the advisory the exploit has been publicly disclosed and may be used; the flaw is not yet in CISA KEV, no standalone PoC is catalogued in the data, and EPSS currently estimates a 0.8% probability of exploitation within 30 days.
What to do: Check Tenda's support/download site for firmware newer than 15.03.06.23 and upgrade as soon as a fixed build is released, since the advisory specifies no fixed version. Until then, disable the Telnet service or restrict access to /goform/telnet, keep the router's Web UI off the WAN (limit management to the trusted LAN or VPN), and block Telnet (TCP/23) from untrusted networks. Review device logs for unexpected requests to /goform/telnet or unexpected Telnet sessions as a sign of probing or compromise.
| Tenda AC1206 router (Web UI, /goform/telnet, TendaTelnet function) | 15.03.06.23 (the only version named in the advisory; other firmware versions are not confirmed either way) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability was determined in Tenda AC1206 15.03.06.23. This vulnerability affects the function TendaTelnet of the file /goform/telnet of the component Web UI. Executing a manipulation can lead to missing authentication. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.
- Weakness
- CWE-287, CWE-306
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.