LiveActive security incident?Get immediate response
CVE Record

CVE-2026-19789: Tenda AC1206 httpd web management interface WifiGuestSet set_wl_guest_iplist stack-based overflow

A vulnerability was determined in Tenda AC1206 15.03.06.23_multi_TD01. This vulnerability affects the function set_wl_guest_iplist of the file /goform/WifiGuestSet of the component httpd web management interface. This manipulation of the argument shareSpeed causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.

CriticalCVSS 9Not KEV-listedUpdated
Glexia's TakeAutomated analysiscritical

Security readout for executives and security teams

Plain-English summary

A flaw in the Tenda AC1206 management interface can overflow memory when it processes a crafted guest Wi-Fi speed value. Successful exploitation could compromise confidentiality, integrity, and availability. Risk is concentrated in devices running firmware 15.03.06.23_multi_TD01, particularly where management access is reachable by untrusted users.

Executive priority

Prioritize identification and containment immediately because the reported impact is critical and proof-of-concept material is public. Remediation urgency is highest for exposed management interfaces. No vendor patch is identified in the supplied sources, so confirm current Tenda guidance and plan isolation or replacement where necessary.

Technical view

CVE-2026-19789 is a stack-based buffer overflow in set_wl_guest_iplist within the /goform/WifiGuestSet handler. Manipulating the shareSpeed argument can corrupt stack memory. The supplied CVSS v2 vector indicates network access, low complexity, and required authentication. The sources report remote exploitation and a public proof of concept, but do not establish successful attacks in the wild.

Likely exposure

Confirmed scope is limited to Tenda AC1206 firmware 15.03.06.23_multi_TD01. Exposure depends on whether the httpd management interface is enabled and reachable. Internet-accessible administration presents the greatest concern, while restricted management networks reduce opportunity. The supplied evidence does not identify other affected versions or products.

Exploitation context

A public disclosure and proof of concept exist, increasing the likelihood of attempted exploitation. The supplied CVSS vector indicates authentication is required. This CVE is not listed as KEV in the bundle, and no cited evidence confirms active exploitation. Treat public exploit availability as elevated risk, not proof of compromise.

Researcher notes

The evidence identifies CWE-119 and CWE-121 and specifically associates shareSpeed processing with stack corruption. Product naming differs across references, including AC1206 and an AC12 submission label; do not broaden scope without vendor or CVE confirmation. Root-cause depth, exploit reliability, privilege outcome, patch status, and telemetry for detecting exploitation remain insufficiently documented.

Mitigation direction

  • Restrict the management interface to trusted administrative networks and authorized users.
  • Disable internet-facing or otherwise unnecessary remote management access.
  • Check Tenda guidance for patched firmware or vendor-approved remediation.
  • Replace or isolate affected devices if no supported fix is available.
  • Monitor management-interface access for unexpected requests and authentication activity.

Validation and detection

  • Inventory Tenda AC1206 devices and record their installed firmware versions.
  • Confirm whether any device runs 15.03.06.23_multi_TD01.
  • Review firewall and routing controls governing management-interface reachability.
  • Verify management access requires strong, unique credentials.
  • Review relevant logs for unusual WifiGuestSet requests or unexplained device instability.
Prepared
Confidence
medium
Sources
6

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-119: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cwe · low confidence lookup

CWE-121: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2026-19789 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Critical
CVSS
9 (2.0)
Known Exploited
No
Published

Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

4CVSS vectors
6Timeline events
1ADP providers
7Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: pocAutomatable: noTechnical Impact: total

CVSS vector scores

4 official scores

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
9CVSS 2.0CriticalAV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR810VulDB
8.8CVSS 3.1HighCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R2.85.9VulDB
8.8CVSS 3.0HighCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R2.85.9VulDB
8.7CVSS 4.0HighCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:PVulDB

Vulnerability scoring details

Base CVSS 4.0 score

8.7High
CVSS 4.0 vector shape for CVE-2026-19789Attack VectorAttack ComplexityAttack RequirementsPrivileges RequiredUser InteractionVS ConfidentialityVS IntegrityVS AvailabilitySS ConfidentialitySS IntegritySS Availability

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Attack Requirements
NonePresent
Privileges Required
NoneLowHigh
User Interaction
NonePassiveActive
VS Confidentiality
HighLowNone
VS Integrity
HighLowNone
VS Availability
HighLowNone
SS Confidentiality
HighLowNone
SS Integrity
HighLowNone
SS Availability
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. Source timelineVulDB

    Advisory disclosed

  2. Source timelineVulDB

    VulDB entry created

  3. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  4. Source timelineVulDB

    VulDB entry last update

  5. CVE publishedCVE Program

    The CVE record was published.

  6. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
TendaAC120615.03.06.23_multi_TD01Listed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.