Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-82693: Tenda AC1206 router allows remote login bypass

CVE-2026-82693 · published 3 days ago
Summary

The web interface of the Tenda AC1206 router (firmware version 15.03.06.23) contains a flaw that lets anyone on the network send a special request and skip the login step. This can be exploited from outside the network, giving attackers access to the router's settings. Update the router firmware to the latest version or disable remote web access until a patch is applied.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
tenda ac1206 15.03.06.23
Original advisory text
Tenda AC1206 Web UI telnet TendaTelnet missing authentication
A vulnerability was determined in Tenda AC1206 15.03.06.23. This vulnerability affects the function TendaTelnet of the file /goform/telnet of the component Web UI. Executing a manipulation can lead to missing authentication. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.
Severity
9.3 Critical
CVSS 2.0: 10.0 (NVD)
CVSS 3.1: 10.0 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-287Improper Authentication
CWE-306Missing Authentication for Critical Function
Timeline
Published31 Aug 2026
Updated2 Sep 2026
First seen31 Aug 2026
Sources
CVE-2026-82693 · MITRE
Monitor software like this
Free during beta