Junglewise Threat Intelligence

CVE-2026-11493: Tenda AC15 weak password requirements in Samba configuration

CVE-2026-11493 · Severity: medium · CVSS 5 · Published 2026-06-08

Technologies: Tenda AC15. Vendors: Tenda.

Executive brief

A security vulnerability has been identified in the Tenda AC15 router, a device used to provide wireless internet in homes and small offices. The flaw affects the Samba component, which is responsible for file sharing across a network. If exploited, this could allow an attacker on the local network to bypass or weaken password requirements, potentially gaining unauthorized access to shared files or the device itself.

Technical details

A vulnerability (CWE-521) exists in the Tenda AC15 router (firmware 15.03.05.19) within the Samba component's configuration file (/etc_ro/smb.conf). The flaw stems from an unknown function that, when manipulated, results in weak password requirements for the service. The attack vector is restricted to the adjacent network (local network), and the exploit is considered high complexity due to the specific conditions required for successful manipulation. An attacker could potentially leverage this to gain unauthorized access to network shares. Public exploit code is reportedly available.

Affected products

  • Tenda AC15 15.03.05.19

Timeline

  • 2026-06-08: disclosed: Initial disclosure via VulDB and NVD

References

Related threats