{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/ac12-15.03.06.23_multi_td01/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-19821"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["AC12 (15.03.06.23_multi_TD01)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Tenda"],"content_html":"\u003cp\u003eA remote buffer overflow vulnerability (CVE-2026-19821) exists in the Tenda AC12 router running firmware version 15.03.06.23_multi_TD01. The vulnerability originates within the 'formSetRebootTimer' function of the '/goform/SetSysAutoRebbotCfg' file, which is part of the device's httpd web management interface. By sending a maliciously crafted 'rebootTime' argument, an authenticated remote attacker can cause a buffer overflow, potentially leading to arbitrary code execution or device instability. The vulnerability has been publicly disclosed with functional exploit code available, posing a significant risk to devices accessible over the network. Defenders should prioritize restricting access to the management interface and monitoring for anomalous HTTP requests targeting the reboot configuration endpoint.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an attacker to execute arbitrary code with the privileges of the web management service. This can lead to a full device compromise, enabling attackers to gain persistence, intercept network traffic, or use the router as a pivot point for further lateral movement within the local network. Given the router's role as a network gateway, this represents a critical threat to the security and integrity of connected residential or small-office environments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImplement network-level segmentation to restrict access to the Tenda AC12 web management interface to trusted administrative IPs only.\u003c/li\u003e\n\u003cli\u003eDeploy detection rules to monitor web server logs for anomalous POST requests to the /goform/SetSysAutoRebbotCfg endpoint.\u003c/li\u003e\n\u003cli\u003eDisable remote web management access on the router immediately if not required.\u003c/li\u003e\n\u003cli\u003eCheck for and apply firmware updates from the vendor if they become available to address CVE-2026-19821.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-14T12:07:56Z","date_published":"2026-08-14T12:07:56Z","id":"https://feed.craftedsignal.io/briefs/2026-08-tenda-ac12-overflow/","summary":"Tenda AC12 router firmware contains a buffer overflow vulnerability in the httpd web management interface, allowing remote attackers to trigger arbitrary code execution via a manipulated reboot parameter.","title":"Remote Buffer Overflow in Tenda AC12 Web Management Interface","url":"https://feed.craftedsignal.io/briefs/2026-08-tenda-ac12-overflow/"}],"language":"en","title":"CraftedSignal Threat Feed - AC12 (15.03.06.23_multi_TD01)","version":"https://jsonfeed.org/version/1.1"}