A vulnerability categorized as critical has been discovered in Tenda AC1206 15.03.06.23_multi_TD01. This affects the function
set_device_name of the file /goform/SetOnlineDevName of the component httpd web management interface. The manipulation of the argument devName results in stack-based buffer overflow.
This vulnerability is cataloged as CVE-2026-19788. The attack may be launched remotely. Furthermore, there is an exploit available.