Executive brief
The Tenda AC1206 WiFi router contains a vulnerability in its web-based administrative interface that allows remote attackers to bypass authentication and gain unauthorized access to the device. Successful exploitation could allow an attacker to reconfigure the router, redirect network traffic, or launch further attacks against connected devices on the network.
Technical details
The vulnerability exists in the TendaTelnet function within the /goform/telnet endpoint of the web UI component in Tenda AC1206 firmware version 15.03.06.23. The flaw is a missing authentication check that allows unauthenticated, remotely reachable HTTP requests to execute telnet-related functionality without proper credential verification. An attacker with network access to the device can manipulate the vulnerable function to bypass authentication controls. The exploit has been publicly disclosed and a proof-of-concept is available.
Affected products
- Tenda AC1206 15.03.06.23
Timeline
- 2026-08-31: disclosed
- other: Exploit code published on GitHub