CVE-2026-1610

HIGH

Tenda AX12 Pro V2 16.03.49.24_cn - Info Disclosure

Title source: llm
STIX 2.1

Description

A vulnerability was found in Tenda AX12 Pro V2 16.03.49.24_cn. Affected by this issue is some unknown functionality of the component Telnet Service. Performing a manipulation results in hard-coded credentials. The attack is possible to be carried out remotely. A high degree of complexity is needed for the attack. The exploitation is known to be difficult. The exploit has been made public and could be used.

Scores

CVSS v3 8.1
EPSS 0.0004
EPSS Percentile 13.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-798 CWE-259
Status published
Products (1)
tenda/ax12_pro_firmware 16.03.49.24_cn
Published Jan 29, 2026
Tracked Since Feb 18, 2026