Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-82694: Tenda AC1206 router allows unauthenticated web access
CVE-2026-82694 · published 3 days ago
Summary
The web management page of the Tenda AC1206 router (firmware version 15.03.06.23) does not properly check who is using it. This lets anyone on the network or internet reach the router’s settings without logging in. Update the router firmware to the latest version or disable remote web management until it is patched.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| tenda | ac1206 | 15.03.06.23 |
Original advisory text
A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the function R7WebsSecurityHandler of the file /goform/ate of the component Web UI. The manipulation leads to missing ...
A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the function R7WebsSecurityHandler of the file /goform/ate of the component Web UI. The manipulation leads to missing authentication. The attack can be initiated remotely. The exploit is publicly available and might be used.
Severity
9.3
Critical
CVSS 2.0: 10.0 (NVD)
CVSS 3.1: 10.0 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-287Improper Authentication
CWE-306Missing Authentication for Critical Function
Timeline
Published31 Aug 2026
Updated2 Sep 2026
First seen31 Aug 2026
Monitor software like this
Free during beta