A vulnerability identified as critical has been detected in Tenda AC1206 15.03.06.23_multi_TD01. This vulnerability affects the function set_wl_guest_iplist of the file /goform/WifiGuestSet of the component httpd web management interface. This manipulation of the argument shareSpeed causes stack-based buffer overflow.

This vulnerability is registered as CVE-2026-19789. Remote exploitation of the attack is possible. Furthermore, an exploit is available.