{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/ac1206-15.03.06.23/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:tenda:ac1206:15.03.06.23:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":10,"id":"CVE-2026-82693"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["AC1206 (15.03.06.23)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","network-security","web-application"],"_cs_type":"advisory","_cs_vendors":["Tenda"],"content_html":"\u003cp\u003eA critical authentication bypass vulnerability has been identified in Tenda AC1206 firmware version 15.03.06.23. The flaw exists within the TendaTelnet function, located in the /goform/telnet file within the Web UI component. This vulnerability allows remote, unauthenticated attackers to interact with the device's administrative functions. The vulnerability has been publicly disclosed and is considered exploitable. Due to the nature of the device as a network-facing router, successful exploitation could lead to full system compromise, enabling attackers to modify device configurations, intercept traffic, or use the device as a pivot point within the local network.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability carries a CVSS v3.1 base score of 10.0, indicating the highest level of severity. Unauthorized access to network infrastructure devices like the Tenda AC1206 exposes residential or small business environments to persistent threats, including traffic interception, DNS hijacking, and internal network reconnaissance.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification of Tenda AC1206 devices within the network inventory. Because this is a router-level vulnerability, detection engineering should prioritize network-based monitoring. Monitor for anomalous HTTP requests directed at the web management interface of identified Tenda devices. Implement network segmentation to isolate such devices from critical assets until firmware patches are applied by the vendor.\u003c/p\u003e\n","date_modified":"2026-08-31T13:58:40Z","date_published":"2026-08-31T13:58:40Z","id":"https://feed.craftedsignal.io/briefs/2026-08-tenda-auth-bypass/","summary":"Tenda AC1206 firmware version 15.03.06.23 contains an authentication bypass vulnerability in the /goform/telnet handler, allowing remote attackers to gain unauthorized access.","title":"Authentication Bypass in Tenda AC1206 Web UI","url":"https://feed.craftedsignal.io/briefs/2026-08-tenda-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - AC1206 (15.03.06.23)","version":"https://jsonfeed.org/version/1.1"}