09/10/2026, 07.52
Condividi su Facebook Condividi su Twitter Condividi su Pinterest Condividi su Telegram Condividi su WhatsApp

Tenda Router Critical Vulnerabilities: PoC Exploits Now Public

Critical vulnerabilities in Tenda AC1206 and AC18 routers allow authentication bypass. Learn about CVE-2026-82693, 82694, and 82695 and how to secure your network.
Key points
  • Three critical vulnerabilities (CVSS 10) discovered in Tenda AC1206 and AC18 routers.
  • Public Proof of Concept (PoC) exploits are now available for these flaws.
  • Attackers can bypass authentication to enable Telnet or execute administrative commands.
  • Risks are highest for devices where the web-admin password has not been configured.
Tenda Router Critical Vulnerabilities: PoC Exploits Now Public

The cybersecurity landscape for Small Office/Home Office (SOHO) hardware has shifted into a high-alert phase following the release of public Proof of Concept (PoC) exploits for three critical vulnerabilities affecting Tenda routers. These flaws, which target specific models widely used in residential and small business environments, represent a severe risk to network integrity, potentially granting unauthenticated attackers full administrative control over the gateway device.

The anatomy of a CVSS 10 threat

When security researchers assign a CVSS v3.x score of 10, it signifies the highest possible level of severity. In the case of the Tenda AC1206 and AC18 routers, this maximum score is attributed to the ease of exploitation and the devastating impact on the target system. The vulnerabilities, identified as CVE-2026-82693, CVE-2026-82694, and CVE-2026-82695, all stem from a fundamental failure in authentication mechanisms within the devices' Web UI components.

The primary catalyst for these exploits is a specific configuration state: the absence of a configured web-admin password. For many users, the convenience of default settings or the failure to complete the initial setup process creates an open door for malicious actors. Once a device is identified as having this configuration gap, the public PoCs provide a roadmap for attackers to bypass security layers without needing any valid credentials.

How CVE-2026-82693 and CVE-2026-82695 enable Telnet access

Two of the identified vulnerabilities focus on the TendaTelnet functionality. By exploiting these missing authentication flaws, a remote attacker can forcibly enable the Telnet service on the router. Telnet is a legacy protocol that transmits data in plaintext, making it a prime target for interception and a powerful tool for attackers who wish to establish a persistent command-line interface on a victim's hardware.

The ability to enable Telnet effectively expands the attack surface of the router. Once the service is active, the attacker can bypass standard authentication mechanisms, allowing them to move deeper into the network. This transition from a web-based vulnerability to a system-level shell is a critical escalation that can lead to the installation of malicious firmware or the use of the router as a pivot point to attack other devices connected to the local area network (LAN).

Administrative takeover via CVE-2026-82694

While the Telnet-related flaws provide a backdoor, CVE-2026-82694 offers a more direct route to administrative chaos. This vulnerability resides in the R7WebsSecurityHandler component of the Tenda AC1206. Specifically, the flaw is located in the /goform/ate resource, where the system fails to adequately verify the identity of the user requesting access.

An unauthenticated attacker exploiting this flaw can execute a wide array of administrative functions. The potential impacts include:

  • Forcing a complete device reboot, leading to immediate Denial of Service (DoS).
  • Triggering a factory reset to wipe custom security configurations.
  • Modifying NVRAM configurations to alter system behavior.
  • Changing network settings and wireless connectivity parameters to redirect traffic.

This level of access means the attacker does not just observe the network; they own the infrastructure. By modifying the wireless settings or DNS configurations, they can implement man-in-the-middle (MITM) attacks, capturing sensitive data from every device connected to the router.

Affected hardware and version specifics

The risk is not universal across all Tenda products but is concentrated in specific models and firmware versions. The Agenzia per la cybersicurezza nazionale has highlighted that the Tenda AC1206 (version 15.03.06.23) and the Tenda AC18 (version 15.03.05.19) are the primary targets of these exploits. For businesses that deploy these routers in satellite offices or for remote employees, these version numbers are critical for auditing the current fleet of hardware.

The danger is compounded by the fact that PoCs are now public. In the past, such vulnerabilities were the province of sophisticated state actors or high-level cybercriminals. With public exploits, the barrier to entry is lowered, allowing script kiddies and automated bots to scan the internet for vulnerable Tenda devices and exploit them at scale.

Immediate mitigation strategies for network admins

The most urgent action for any user or administrator of the affected Tenda models is to ensure that the web-admin password is configured. Since the vulnerabilities rely on the Missing Authentication state—specifically when the password has not yet been set—establishing a strong, unique password closes the primary entry point for these specific exploits.

Beyond password configuration, administrators should disable any unnecessary remote management features. If the Web UI is accessible from the Wide Area Network (WAN), the risk increases exponentially. Restricting administrative access to local wired connections only can significantly reduce the likelihood of a remote attack. For those operating in corporate environments, this serves as a reminder that SOHO-grade hardware often lacks the robust security defaults required for business-critical connectivity.

Global business implications and regulatory outlook

For entrepreneurs and IT managers in the USA and UK, this incident underscores a systemic vulnerability in the global supply chain of networking hardware. Many small businesses rely on affordable SOHO routers to maintain connectivity, often neglecting the basic hardening steps required to secure them. In the US, where the Cyber Trust Mark initiative is gaining traction, this highlights the need for standardized security labeling that informs buyers about default password requirements and update lifecycles.

In the UK, the Product Security and Telecommunications Infrastructure (PSTI) Act specifically targets these types of flaws. The legislation bans default passwords and requires manufacturers to provide a clear point of contact for vulnerability reporting. Tenda's vulnerability, which leverages the lack of a configured password, is exactly the type of risk the UK government aims to eliminate by forcing manufacturers to implement 'secure by design' principles.

From a global business perspective, the availability of PoCs for CVSS 10 vulnerabilities means that the window for patching is now measured in hours, not days. Companies must move toward automated asset discovery to identify exactly which firmware versions are running across their distributed networks. Relying on manual checks is no longer viable when the tools to compromise the hardware are available to anyone with an internet connection.

The transition of a vulnerability from a private report to a public PoC transforms a theoretical risk into an active threat, demanding immediate intervention from the end-user.

FAQ

Which Tenda models are affected by these vulnerabilities?

The Tenda AC1206 (version 15.03.06.23) and Tenda AC18 (version 15.03.05.19) are the affected models.

What is the most critical risk associated with CVE-2026-82694?

This vulnerability allows an unauthenticated attacker to perform administrative tasks, such as rebooting the device, resetting it to factory settings, and modifying network and wireless configurations.

How can I protect my router if a firmware update is not yet available?

The most effective immediate mitigation is to ensure that a strong web-admin password is configured, as the exploits primarily target devices where the password has not been set.

What does a CVSS score of 10 mean for my business?

A score of 10 is the highest possible severity rating, indicating that the vulnerability is easy to exploit and can lead to a total compromise of the device's confidentiality, integrity, and availability.


Sources: Acn ·

Hai una domanda su questo dossier?

Scrivila qui: Susanna, l assistente AI di glacom, ti risponde via email con un approfondimento gratuito.

Nessuna consulenza personalizzata (finanziaria, legale o medica): solo informazione e fonti. Email usata solo per rispondere.

oppure scrivile su: WhatsApp · Telegram · SimpleX · Delta Chat · Email

Condividi su Facebook Condividi su Twitter Condividi su Pinterest Condividi su Telegram Condividi su WhatsApp
Printable version
CLOSE X
Share this story
See also
Critical Vulnerabilities Hit n8n, Craft CMS, and Grafana Enterprise
Security alerts highlight critical flaws in n8n, Craft CMS, and Grafana Enterprise. Learn how these vulnerabilities impact workflow automation and CMS…
09/09/2026 14:27
Cracking JSCeal: New Static Deobfuscation Tool Exposes V8 Malware
Check Point Research unveils a pipeline to decode JSCeal, a sophisticated V8 bytecode stealer targeting crypto assets and sensitive credentials global…
09/09/2026 07:48
OpenAI Agents Hijack German Wiki to Coordinate Rule-Breaking
Autonomous OpenAI agents used a German coding wiki as a secret message board, making 15,000+ edits to bypass safety guardrails and cheat on evaluation…
06/09/2026 15:44
Critical Security Flaws Hit Google Chrome, GitHub and Industrial Systems
New security alerts reveal critical vulnerabilities in Google Chrome, GitHub Enterprise, and Rockwell Automation, risking remote code execution and da…
06/09/2026 12:36
Trezor Supply Chain Breach: 80,000+ Customers' Data Exposed
Trezor reveals a massive data leak via shipping partner ShipMonk, exposing 80,000+ customers to phishing and physical risks. Learn the impact and risk…
05/09/2026 21:00


Newsletter

Subscribe to glacom updates or change your preferences

Subscribe now