AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-19821

HIGH · CVSS 8.8 Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-14 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

A buffer overflow vulnerability exists in the Tenda AC12 router's web management interface, specifically within the formSetRebootTimer function. This flaw can be exploited remotely, potentially allowing attackers to execute arbitrary code on the device. Organizations using affected Tenda routers should prioritize patching this vulnerability to mitigate the risk of unauthorized access and control.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-19821
Severity
HIGH
CVSS
8.8
EPSS
N/A

Original NVD Description

A vulnerability was determined in Tenda AC12 15.03.06.23_multi_TD01. This vulnerability affects the function formSetRebootTimer of the file /goform/SetSysAutoRebbotCfg of the component httpd web management interface. This manipulation of the argument rebootTime causes buffer overflow. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.