ZeroHour

CVE-2026-82693

Missing Authentication in Tenda AC1206 Web UI Telnet Endpoint

CVSS 4.0
9.3 critical
EPSS
<1%p54
Published
()
Modified
AI analysis

CVE-2026-82693 is a missing-authentication flaw (CWE-306/CWE-287) in the TendaTelnet function of the file /goform/telnet, part of the Web UI of the Tenda AC1206 router running firmware 15.03.06.23. An unauthenticated remote attacker can trigger the flaw by sending a manipulated request to this endpoint, which bypasses authentication on the Telnet component. With a CVSS 4.0 base score of 9.3 and high ratings for confidentiality, integrity, and availability (including on subsequent systems), an attacker who reaches this endpoint could gain substantial, potentially full, control of the device, though the advisory does not detail the exact post-access capabilities. Operators of Tenda AC1206 routers on the affected firmware are exposed, particularly devices whose Web UI is reachable from the internet or untrusted networks. Per the advisory the exploit has been publicly disclosed and may be used; the flaw is not yet in CISA KEV, no standalone PoC is catalogued in the data, and EPSS currently estimates a 0.8% probability of exploitation within 30 days.

What to do: Check Tenda's support/download site for firmware newer than 15.03.06.23 and upgrade as soon as a fixed build is released, since the advisory specifies no fixed version. Until then, disable the Telnet service or restrict access to /goform/telnet, keep the router's Web UI off the WAN (limit management to the trusted LAN or VPN), and block Telnet (TCP/23) from untrusted networks. Review device logs for unexpected requests to /goform/telnet or unexpected Telnet sessions as a sign of probing or compromise.

Affected
Tenda AC1206 router (Web UI, /goform/telnet, TendaTelnet function)15.03.06.23 (the only version named in the advisory; other firmware versions are not confirmed either way)
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability was determined in Tenda AC1206 15.03.06.23. This vulnerability affects the function TendaTelnet of the file /goform/telnet of the component Web UI. Executing a manipulation can lead to missing authentication. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.

Weakness
CWE-287, CWE-306
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.