CVE-2026-0581 | Tenda AC1206 15.03.06.23 httpd /goform/BehaviorManager formBehaviorManager modulename/option/data/switch command injection
A vulnerability classified as critical was found in Tenda AC1206 15.03.06.23. Affected by this issue is the function formBehaviorManager of the file /goform/BehaviorManager of the component httpd. Executing a manipulation of the argument modulename/option/data/switch can lead to command injection.
This vulnerability is tracked as CVE-2026-0581. The attack can be launched remotely. Moreover, an exploit is present.