A vulnerability was determined in Tenda AC1206 15.03.06.23_multi_TD01. This vulnerability affects the function set_wl_guest_iplist of the file /goform/WifiGuestSet of the component httpd web management interface. This manipulation of the argument shareSpeed causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
Security readout for executives and security teams
Plain-English summary
A flaw in the Tenda AC1206 management interface can overflow memory when it processes a crafted guest Wi-Fi speed value. Successful exploitation could compromise confidentiality, integrity, and availability. Risk is concentrated in devices running firmware 15.03.06.23_multi_TD01, particularly where management access is reachable by untrusted users.
Executive priority
Prioritize identification and containment immediately because the reported impact is critical and proof-of-concept material is public. Remediation urgency is highest for exposed management interfaces. No vendor patch is identified in the supplied sources, so confirm current Tenda guidance and plan isolation or replacement where necessary.
Technical view
CVE-2026-19789 is a stack-based buffer overflow in set_wl_guest_iplist within the /goform/WifiGuestSet handler. Manipulating the shareSpeed argument can corrupt stack memory. The supplied CVSS v2 vector indicates network access, low complexity, and required authentication. The sources report remote exploitation and a public proof of concept, but do not establish successful attacks in the wild.
Likely exposure
Confirmed scope is limited to Tenda AC1206 firmware 15.03.06.23_multi_TD01. Exposure depends on whether the httpd management interface is enabled and reachable. Internet-accessible administration presents the greatest concern, while restricted management networks reduce opportunity. The supplied evidence does not identify other affected versions or products.
Exploitation context
A public disclosure and proof of concept exist, increasing the likelihood of attempted exploitation. The supplied CVSS vector indicates authentication is required. This CVE is not listed as KEV in the bundle, and no cited evidence confirms active exploitation. Treat public exploit availability as elevated risk, not proof of compromise.
Researcher notes
The evidence identifies CWE-119 and CWE-121 and specifically associates shareSpeed processing with stack corruption. Product naming differs across references, including AC1206 and an AC12 submission label; do not broaden scope without vendor or CVE confirmation. Root-cause depth, exploit reliability, privilege outcome, patch status, and telemetry for detecting exploitation remain insufficiently documented.
Mitigation direction
Restrict the management interface to trusted administrative networks and authorized users.
Disable internet-facing or otherwise unnecessary remote management access.
Check Tenda guidance for patched firmware or vendor-approved remediation.
Replace or isolate affected devices if no supported fix is available.
Monitor management-interface access for unexpected requests and authentication activity.
Validation and detection
Inventory Tenda AC1206 devices and record their installed firmware versions.
Confirm whether any device runs 15.03.06.23_multi_TD01.
Review firewall and routing controls governing management-interface reachability.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-119: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
4CVSS vectors
6Timeline events
1ADP providers
7Source links
SSVC decision data
CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: pocAutomatable: noTechnical Impact: total
CVSS vector scores
4 official scores
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.