Tenda AC1206 Web UI Missing Authentication Vulnerabilities (CVE-2026-82693 and CVE-2026-82694)

Release Date: 31st August 2026 (Added 9 September 2026)

Impact : CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations, System/Network administrators, and members of the general public that use a Tenda AC1206 wireless router. This alert is intended to be understood by both technical and general readers.

What is it?

CVE-2026-82693 and CVE-2026-82694 are two missing-authentication vulnerabilities in the Web UI of the Tenda AC1206, a mass-market AC1900-class dual-band Wi-Fi router sold through general electronics retailers worldwide (Amazon, eBay, and other consumer retail channels), with no dependency on any specific ISP.

Reference

  1. https://www.cve.org/CVERecord?id=CVE-2026-82693
  2. https://www.cve.org/CVERecord?id=CVE-2026-82694