📦 Ac1206 Firmware

by Tenda

🔍 What is Ac1206 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-10432

CRITICAL CVSS 9.8 Sep 15, 2025

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC1206 routers via a stack-based buffer overflow in the HTTP request handler. Attackers can exploit this by sending specia...

CVE-2025-9523

CRITICAL CVSS 9.8 Aug 27, 2025

This vulnerability in Tenda AC1206 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the GetParentControlInfo function. Attackers can exploit this without ...

CVE-2023-38936

CRITICAL CVSS 9.8 Aug 7, 2023

This CVE describes a stack overflow vulnerability in multiple Tenda router models via the speed_dir parameter in the formSetSpeedWan function. Attackers can exploit this to execute arbitrary code or c...

CVE-2023-37717

CRITICAL CVSS 9.8 Jul 14, 2023

This vulnerability allows remote attackers to execute arbitrary code on affected Tenda routers via a stack overflow in the fromDhcpListClient function. Attackers can exploit this by sending specially ...

CVE-2023-37711

CRITICAL CVSS 9.8 Jul 10, 2023

This vulnerability allows remote attackers to execute arbitrary code on affected Tenda routers via a stack overflow in the deviceId parameter. Attackers can gain full control of the device without aut...

CVE-2025-7544

HIGH CVSS 8.8 Jul 13, 2025

A critical stack-based buffer overflow vulnerability in Tenda AC1206 routers allows remote attackers to execute arbitrary code by manipulating the deviceList parameter in the formSetMacFilterCfg funct...

CVE-2025-4299

HIGH CVSS 8.8 May 6, 2025

A critical buffer overflow vulnerability in Tenda AC1206 routers allows remote attackers to execute arbitrary code by exploiting the setSchedWifi function. This affects all Tenda AC1206 routers runnin...

CVE-2025-3328

HIGH CVSS 8.8 Apr 7, 2025

A critical buffer overflow vulnerability in Tenda AC1206 routers allows remote attackers to execute arbitrary code by manipulating the ssid or timeZone parameters. This affects the form_fast_setting_w...

CVE-2024-10434

HIGH CVSS 8.8 Oct 28, 2024

A critical stack-based buffer overflow vulnerability in Tenda AC1206 routers allows remote attackers to execute arbitrary code by manipulating the 'arg' parameter in the ate_Tenda_mfg_check_usb/ate_Te...

CVE-2026-0581

MEDIUM CVSS 6.3 Jan 5, 2026

This CVE describes a command injection vulnerability in Tenda AC1206 routers that allows remote attackers to execute arbitrary commands on affected devices. Attackers can exploit the vulnerability by ...

CVE-2024-10280

MEDIUM CVSS 6.5 Oct 23, 2024

A null pointer dereference vulnerability in Tenda routers allows remote attackers to cause denial of service by manipulating the Content-Length argument in the websReadEvent function. This affects mul...

CVE-2024-9793

MEDIUM CVSS 6.3 Oct 10, 2024

This critical vulnerability in Tenda AC1206 routers allows remote attackers to execute arbitrary commands via command injection in the ate_iwpriv_set/ate_ifconfig_set functions. Attackers can gain con...