CVE-2026-1610Disclosure(tenda / ax12_pro)

LOWCVSS 8.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was found in Tenda AX12 Pro V2 16.03.49.24_cn. Affected by this issue is some unknown functionality of the component Telnet Service. Performing a manipulation results in hard-coded credentials. The attack is possible to be carried out remotely. A high degree of complexity is needed for the attack. The exploitation is known to be difficult. The exploit has been made public and could be used.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-259CWE-798

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ax12_pro
  • ax12_pro_firmware

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
ax12_proax12_pro_firmware

2 versions affected across 2 products

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-01-29: 2Technical Details · 2026-01-29: 101-29
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    General

    CVE-2026-1610 A vulnerability was found in Tenda AX12 Pro V2 16.03.49.24_cn. Affected by this issue is some unknown functionality of the component Telnet Service. Performing a manipu… https://www.cve.org/CVERecord?id=CVE-2026-1610

    Post summary

    The post reports a CVE (CVE-2026-1610) affecting a Tenda AX12 Pro V2 router’s telnet service but offers no further technical detail, evidence of exploitation, or mitigation information.

    00000255
    56.5K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-1610: Tenda AX12 Pro V2 Telnet Service ... Hard-coded Telnet creds in Tenda AX12 Pro V2 routers offer full remote control despite high attack complexity - public e... https://zerodaysignal.com/vulnerability/CVE-2026-1610 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces a CVE‑2026‑1610 vulnerability in Tenda AX12 Pro V2 routers, highlighting hard‑coded Telnet credentials that enable full remote control, with high attack complexity.

    00000181
    132 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendaax12_pro2.0--
OStendaax12_pro_firmware16.03.49.24_cn--

Explore more