CVE-2026-19789: Tenda AC1206 httpd web management interface WifiGuestSet set_wl_guest_iplist stack-based overflow
A vulnerability was determined in Tenda AC1206 15.03.06.23multiTD01. This vulnerability affects the function setwlguestiplist of the file /goform/WifiGuestSet of the component httpd web management interface. This manipulation of the argument shareSpeed causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19789?
CVE-2026-19789 has a high severity rating of 8.8.
What type of vulnerability is CVE-2026-19789?
CVE-2026-19789 is a stack-based buffer overflow vulnerability.
How do I fix CVE-2026-19789?
To fix CVE-2026-19789, apply the latest firmware updates provided by Tenda for the AC1206 device.
What affects CVE-2026-19789?
CVE-2026-19789 affects the Tenda AC1206 device's httpd web management interface, specifically the set_wl_guest_iplist function.
Can CVE-2026-19789 be exploited remotely?
Yes, CVE-2026-19789 can be exploited remotely due to its nature as a remote code execution vulnerability.