Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 23 Feb 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:o:tenda:ac1206_firmware:*:*:*:*:*:*:*:* |
Mon, 12 Jan 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenda ac1206 Firmware
|
|
| CPEs | cpe:2.3:h:tenda:ac1206:-:*:*:*:*:*:*:* cpe:2.3:o:tenda:ac1206_firmware:15.03.06.23:*:*:*:*:*:*:* |
|
| Vendors & Products |
Tenda ac1206 Firmware
|
Tue, 06 Jan 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenda
Tenda ac1206 |
|
| Vendors & Products |
Tenda
Tenda ac1206 |
Tue, 06 Jan 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 05 Jan 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was determined in Tenda AC1206 15.03.06.23. Affected by this issue is the function formBehaviorManager of the file /goform/BehaviorManager of the component httpd. Executing a manipulation of the argument modulename/option/data/switch can lead to command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. | |
| Title | Tenda AC1206 httpd BehaviorManager formBehaviorManager command injection | |
| Weaknesses | CWE-74 CWE-77 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-02-23T08:13:25.661Z
Reserved: 2026-01-04T06:49:02.040Z
Link: CVE-2026-0581
Updated: 2026-01-05T21:12:44.579Z
Status : Analyzed
Published: 2026-01-05T09:15:54.867
Modified: 2026-04-29T01:00:01.613
Link: CVE-2026-0581
No data.
OpenCVE Enrichment
Updated: 2026-04-18T08:30:35Z