๐Ÿ” CVE Alert

CVE-2026-0581

MEDIUM 6.3

Tenda AC1206 httpd BehaviorManager formBehaviorManager command injection

CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was determined in Tenda AC1206 15.03.06.23. Affected by this issue is the function formBehaviorManager of the file /goform/BehaviorManager of the component httpd. Executing a manipulation of the argument modulename/option/data/switch can lead to command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.

CWE CWE-77 CWE-74
Vendor tenda
Product ac1206
Published Jan 5, 2026
Last Updated Feb 23, 2026
Stay Ahead of the Next One

Get instant alerts for tenda ac1206

Be the first to know when new medium vulnerabilities affecting tenda ac1206 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Tenda / AC1206
15.03.06.23

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/?id.339473 vuldb.com: https://vuldb.com/?ctiid.339473 vuldb.com: https://vuldb.com/?submit.731193 github.com: https://github.com/ccc-iotsec/cve-/blob/Tenda/Tenda%20AC1206%E5%91%BD%E4%BB%A4%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md tenda.com.cn: https://www.tenda.com.cn/

Credits

๐Ÿ” 2160288544 (VulDB User)