VYPR
advisoryPublished Aug 31, 2026· Updated Sep 1, 2026· 1 source

Tenda Routers: Five Critical Vulnerabilities Including Hardcoded Credentials and Auth Bypass Disclosed Together

Key findings • Five critical vulnerabilities disclosed in Tenda routers between August 30-31, 2026. • Flaws include missing authentication, buffer overflows, and hardcoded credentials. • …

Key findings

  • Five critical vulnerabilities disclosed in Tenda routers between August 30-31, 2026.
  • Flaws include missing authentication, buffer overflows, and hardcoded credentials.
  • Remote exploitation is possible, with some exploits publicly available.
  • Affected models include Tenda HG21, AC18, AC1206, and HG10.
  • Potential for root access and arbitrary code execution poses significant risk.

On August 30th and 31st, 2026, a batch of five critical vulnerabilities was disclosed, affecting multiple Tenda router models. These flaws, primarily involving missing authentication and buffer overflows, could allow remote attackers to gain root access or execute arbitrary code. The vulnerabilities were reported by multiple sources, highlighting a significant security concern for Tenda device users.

The disclosed vulnerabilities can be grouped by their impact and affected components. Three critical vulnerabilities (CVE-2026-82695, CVE-2026-82694, and CVE-2026-82693) stem from missing authentication flaws in the Telnet and Web UI components of Tenda devices. Specifically, CVE-2026-82695 affects the Telnet Handler in Tenda AC18, while CVE-2026-82694 and CVE-2026-82693 target the Web UI's ate and TendaTelnet functions in Tenda AC1206. These allow remote attackers to bypass authentication mechanisms.

Another critical vulnerability, CVE-2026-82542, identified in the Tenda HG10, exploits a buffer overflow in the Boa Web Server's IPv6 routing function. This flaw can be triggered remotely by manipulating the destNet argument, potentially leading to code execution.

Finally, CVE-2026-38577, found in the Tenda HG21, involves insecure hardcoded credentials in the Admin account. This vulnerability allows attackers to gain root access to the device, posing a severe risk to network security.

Exploitation context for these vulnerabilities is significant, with multiple reports indicating that exploits for CVE-2026-82695, CVE-2026-82694, and CVE-2026-82693 have been publicly released and may be actively used. The remote nature of these attacks and the potential for root access or code execution underscore the urgency for users to address these security issues.

Information regarding specific patches or updated firmware versions for all affected Tenda models was not immediately available in the disclosure details. However, given the severity and the public availability of exploits, users are strongly advised to consult Tenda's official support channels for the latest security advisories and firmware updates.

The coordinated disclosure of these critical vulnerabilities highlights a widespread security weakness across several Tenda router models. Users of Tenda HG21, AC18, AC1206, and HG10 devices are urged to prioritize updating their firmware as soon as patches become available to mitigate the risk of remote exploitation and unauthorized access. The potential for attackers to gain root privileges or execute arbitrary code necessitates immediate attention to secure these network devices.

Synthesized by Vypr AI