boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-19821HIGH
Tenda AC12 httpd web management interface SetSysAutoRebbotCfg formSetRebootTimer buffer overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0047   38.6     —
AFFECTED
  Product  Versions                  Fixed
  AC12     15.03.06.23_multi_TD01 –  —
TIMELINE
  Aug 14  Reserved by VulDB
  Aug 14  Published (CNA: VulDB)
  Aug 18  EXPLOIT PUBLISHED — CVE-2026-19821 (Tenda AC12). Public exploit reference added.
CWE-119, CWE-120 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred

Description

A vulnerability was determined in Tenda AC12 15.03.06.23_multi_TD01. This vulnerability affects the function formSetRebootTimer of the file /goform/SetSysAutoRebbotCfg of the component httpd web management interface. This manipulation of the argument rebootTime causes buffer overflow. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
August 14, 2026ReservedReserved by VulDB
August 14, 2026PublishedPublished (CNA: VulDB)
August 18, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2026-19821 (Tenda AC12). Public exploit reference added.

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
TendaAC1215.03.06.23_multi_TD01

Weaknesses

CWE-119 · CWE-120

References (6)

Related

Authoritative record: CVE-2026-19821 at cve.org

Vendors: tenda

Weaknesses: CWE-119 · CWE-120

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-19821 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.