Tenda PoCs Exploit Default-State Router Trust

CSIRT Italia said public proof-of-concept code is now available for three critical Tenda flaws in the AC1206 and AC18 routers, including CVE-2026-82693, CVE-2026-82694, and CVE-2026-82695. The issue hits devices whose web-admin password has never been set. In that factory-default state, the web UI trusts special management paths without authentication. An attacker can turn on Telnet or trigger admin actions such as reboot, factory reset, and configuration changes, so the box is exposed before anyone has “hardened” it in the usual sense. For operators, the exposure is not just a router bug but a setup-state problem: any unit still sitting at an uninitialized admin screen may already be reachable as a remote management foothold. That makes deployed default-config devices the part of the fleet that now carries the risk.

Part of the PlainSec briefing for 2026-09-01

Every edition of this story: Tenda PoCs Exploit Default-State Router Trust

Sources