What is CVE-2026-19788?
A stack-based buffer overflow vulnerability (CVE-2026-19788) has been identified in the `set_device_name` function of the httpd web management interface on Tenda AC1206 routers. The flaw is caused by improper handling of the `devName` argument in `/goform/SetOnlineDevName`, potentially allowing remote code execution. Affected users should monitor for official Tenda patches and restrict access to the management interface.
Azərbaycanca: Tenda AC1206 routerin httpd veb idarəetmə interfeysindəki `set_device_name` funksiyasında stack-based buffer overflow zəifliyi aşkarlanıb (CVE-2026-19788). Bu zəiflik `devName` arqumentinin düzgün yoxlanılmaması səbəbindən uzaqdan kod icrasına imkan verə bilər. Cihaz sahibləri Tenda-nın rəsmi yamaq buraxılışını izləməli və idarəetmə interfeysinə girişi məhdudlaşdırmalıdır.
Related CVEs
link basis: same weakness class CWE-119; shared vendor: Tenda
FAQ2
In which interface of the Tenda AC1206 router was CVE-2026-19788 discovered?
This vulnerability was discovered in the `set_device_name` function of the router's httpd web management interface.
What is the root cause of the buffer overflow issue in Tenda AC1206?
The flaw is caused by improper handling of the `devName` argument in the `/goform/SetOnlineDevName` operation.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.