{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/ac1206/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-19788"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["AC1206"],"_cs_severities":["high"],"_cs_tags":["vulnerability","remote-code-execution","network-security","buffer-overflow"],"_cs_type":"advisory","_cs_vendors":["Tenda"],"content_html":"\u003cp\u003eA vulnerability identified as CVE-2026-19788 affects the Tenda AC1206 router, specifically firmware version 15.03.06.23_multi_TD01. The issue resides within the httpd web management interface, where the function 'set_device_name' within the file '/goform/SetOnlineDevName' fails to properly validate the input provided to the 'devName' argument. This failure leads to a stack-based buffer overflow when a maliciously crafted input is processed. Because the interface is accessible remotely, an attacker can leverage this flaw to trigger an overflow, potentially leading to a denial of service or arbitrary code execution with the privileges of the web service. Proof-of-concept exploit code has been made public, increasing the risk of exploitation by unauthorized actors against internet-exposed devices.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify Tenda AC1206 devices exposed to the internet.\u003c/li\u003e\n\u003cli\u003eAttacker authenticates to the target device's web management interface (httpd).\u003c/li\u003e\n\u003cli\u003eAttacker identifies the '/goform/SetOnlineDevName' endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP POST request containing an excessively long string in the 'devName' parameter.\u003c/li\u003e\n\u003cli\u003eThe httpd service passes the 'devName' value to the vulnerable 'set_device_name' function.\u003c/li\u003e\n\u003cli\u003eThe lack of bounds checking causes the supplied input to overwrite adjacent memory on the stack.\u003c/li\u003e\n\u003cli\u003eAttacker successfully redirects program execution flow to arbitrary code, resulting in system compromise.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-19788 allows a remote attacker to gain control over the affected Tenda AC1206 router. Given the function's role in system administration, this vulnerability could be used to facilitate persistent access, exfiltration of configuration data, or the hijacking of network traffic traversing the device. The impact is significant for home and small business users relying on this hardware for network security.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately restrict access to the httpd web management interface to trusted local network segments only.\u003c/li\u003e\n\u003cli\u003eDisable remote management features on the Tenda AC1206 router until a patch is applied.\u003c/li\u003e\n\u003cli\u003eMonitor network traffic for HTTP POST requests directed at '/goform/SetOnlineDevName' that contain unusually large or anomalous strings in the 'devName' parameter.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule below to detect potential exploitation attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-14T06:06:16Z","date_published":"2026-08-14T06:06:16Z","id":"https://feed.craftedsignal.io/briefs/2026-08-tenda-ac1206-overflow/","summary":"A stack-based buffer overflow in the Tenda AC1206 firmware version 15.03.06.23_multi_TD01 allows remote attackers to trigger memory corruption via the httpd web management interface.","title":"Stack-Based Buffer Overflow in Tenda AC1206 Web Interface","url":"https://feed.craftedsignal.io/briefs/2026-08-tenda-ac1206-overflow/"}],"language":"en","title":"CraftedSignal Threat Feed - AC1206","version":"https://jsonfeed.org/version/1.1"}