A missing-authentication flaw in the Tenda AC1206 web UI lets remote attackers reach the router's telnet-enabling handler without credentials, and the source record indicates a public exploit has been disclosed and may already be circulating.
What Is It
CVE-2026-82693 is a missing authentication vulnerability in the TendaTelnet function of /goform/telnet, part of the Web UI component on Tenda AC1206 firmware 15.03.06.23. Manipulating a request to this endpoint reaches functionality that should be gated behind authentication. The issue is classified under CWE-287 (Improper Authentication) and CWE-306 (Missing Authentication for Critical Function), and it can be triggered remotely.
Why It Matters
The CVSS v3.1 base score is 10.0 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, network attack vector, low complexity, no privileges, no user interaction, and a changed scope with high confidentiality, integrity, and availability impact. Note that the supplied record prints this metric set behind a CVSS:4.0/ prefix; the metrics themselves (particularly S:C, which v4.0 replaced with the SC/SI/SA subsequent-system metrics) are v3.1 metrics, which suggests the prefix in the source is most likely a labeling error rather than a second v4.0 vector.
Separately, CVSS v4.0 rates it 9.3 (CRITICAL) with exploit maturity marked as Proof-of-Concept. CVSS v2 scores it 10.0 with complete impact across all three properties.
Per the NVD description, "the exploit has been publicly disclosed and may be utilized." There is no CISA KEV entry for this CVE in the supplied data, so active in-the-wild exploitation is not confirmed, but a public PoC against an unauthenticated, network-reachable consumer router endpoint is a short path to opportunistic abuse.
What's Vulnerable
- Vendor: Tenda
- Product: AC1206
- Affected version: firmware 15.03.06.23
- Component: Web UI,
/goform/telnet, functionTendaTelnet - CPE:
cpe:2.3:o:tenda:ac1206_firmware:*:*:*:*:*:*:*:*
Only version 15.03.06.23 is listed as affected in the supplied record.
Patch Status
No patch, fixed version, or vendor advisory is present in the supplied source material, and no required remediation action or KEV due date is specified. The record was published and last modified 2026-08-31 with a vulnerability status of Received, meaning NVD analysis is not yet complete. The only vendor reference supplied is Tenda's main site.
Sources
- NVD, CVE-2026-82693: https://nvd.nist.gov/vuln/detail/CVE-2026-82693
- VulDB, CVE-2026-82693: https://vuldb.com/cve/CVE-2026-82693
- VulDB, Vulnerability 397181: https://vuldb.com/vuln/397181
- VulDB, Threat Intelligence 397181: https://vuldb.com/vuln/397181/cti
- VulDB, Submission 894235: https://vuldb.com/submit/894235
- Researcher write-up (dxz0069, GitHub): https://github.com/dxz0069/WAVLINK-WN530H4-Command-Injection-in-set_add_routing/blob/main/TENDA-AC1206-TELNET-DEFAULT-UNAUTH-001-vulndb.md
- Tenda (vendor): https://www.tenda.com.cn/