Skip to content
Threat Feed
critical advisory

Authentication Bypass in Tenda AC1206 Web UI

Tenda AC1206 firmware version 15.03.06.23 contains an authentication bypass vulnerability in the /goform/telnet handler, allowing remote attackers to gain unauthorized access.

CVE search metadata

CVE search record: CVE-2026-82693. Severity: critical. CVSS: 10.0. KEV: no. Product: AC1206 (15.03.06.23). Brief: Authentication Bypass in Tenda AC1206 Web UI. Brief link: https://feed.craftedsignal.io/briefs/2026-08-tenda-auth-bypass/

A critical authentication bypass vulnerability has been identified in Tenda AC1206 firmware version 15.03.06.23. The flaw exists within the TendaTelnet function, located in the /goform/telnet file within the Web UI component. This vulnerability allows remote, unauthenticated attackers to interact with the device's administrative functions. The vulnerability has been publicly disclosed and is considered exploitable. Due to the nature of the device as a network-facing router, successful exploitation could lead to full system compromise, enabling attackers to modify device configurations, intercept traffic, or use the device as a pivot point within the local network.

Impact

The vulnerability carries a CVSS v3.1 base score of 10.0, indicating the highest level of severity. Unauthorized access to network infrastructure devices like the Tenda AC1206 exposes residential or small business environments to persistent threats, including traffic interception, DNS hijacking, and internal network reconnaissance.

Recommendation

Prioritize the identification of Tenda AC1206 devices within the network inventory. Because this is a router-level vulnerability, detection engineering should prioritize network-based monitoring. Monitor for anomalous HTTP requests directed at the web management interface of identified Tenda devices. Implement network segmentation to isolate such devices from critical assets until firmware patches are applied by the vendor.


Immediate actions

Isolate Tenda AC1206 devices from the public internet.

IT Operations 24h

Mitigations

Check for and apply firmware updates from Tenda; restrict access to /goform/telnet.

immediate IT Operations

CVE-2026-82693

Detection coverage 1

Detect CVE-2026-82693 Exploitation - HTTP Request to /goform/telnet

critical

Detects exploitation attempts against Tenda AC1206 routers by monitoring for incoming HTTP requests to the vulnerable /goform/telnet endpoint.

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →