What is CVE-2026-19821?
This vulnerability is a buffer overflow in the `formSetRebootTimer` function of Tenda AC12 routers, caused by manipulating the `rebootTime` argument via the httpd web management interface. A remote attacker could compromise the device. Access to the administration interface should be restricted until Tenda releases a patch.
Azərbaycanca: Bu boşluq Tenda AC12 router-in `formSetRebootTimer` funksiyasındakı `rebootTime` arqumentinin manipulyasiyası nəticəsində yaranan buffer overflow zəifliyidir. Uzaqdan hücum edən şəxs httpd interfeysi vasitəsilə cihazı ələ keçirə bilər. Tenda tərəfindən rəsmi yamaq yayımlanana qədər cihazın idarəetmə interfeysinə giriş məhdudlaşdırılmalıdır.
Related CVEs
link basis: same weakness class CWE-119; shared vendor: Tenda
FAQ2
Where is the CVE-2026-19821 vulnerability located in the Tenda AC12 router?
The vulnerability is a buffer overflow in the `formSetRebootTimer` function caused by manipulation of the `rebootTime` argument.
What is recommended to mitigate CVE-2026-19821 until Tenda provides an official patch?
Access to the device administration interface should be restricted.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.