What is CVE-2026-19789?
A stack-based buffer overflow vulnerability exists in the set_wl_guest_iplist function of the Tenda AC1206 router's httpd web management interface. It can be exploited remotely, potentially leading to device compromise. Restrict access to the remote management interface until a vendor patch is available.
Azərbaycanca: Tenda AC1206 routerin httpd interfeysindəki set_wl_guest_iplist funksiyasında stack-based buffer overflow zəifliyi aşkar edilib. Uzaqdan istismar mümkündür, cihazın idarə edilməsinə təsir edə bilər. İstehsalçı tərəfindən yeniləmə təqdim olunana qədər cihazın uzaqdan idarəetmə interfeysinə giriş məhdudlaşdırılmalıdır.
Related CVEs
link basis: same weakness class CWE-119; shared vendor: Tenda
FAQ2
In which component of the Tenda AC1206 router was CVE-2026-19789 discovered?
The vulnerability was discovered in the set_wl_guest_iplist function of the device's httpd web management interface.
What temporary step is recommended to protect against CVE-2026-19789 until a vendor patch is available?
Access to the remote management interface of the device should be restricted.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.