CVE-2026-1610: Tenda AX12 Pro Firmware

High severity, CVSS 8.1. EPSS: 0.7% chance of exploitation in the next 30 days.

A vulnerability was found in Tenda AX12 Pro V2 16.03.49.24_cn. Affected by this issue is some unknown functionality of the component Telnet Service. Performing a manipulation results in hard-coded credentials. The attack is possible to be carried out remotely. A high degree of complexity is needed for the attack. The exploitation is known to be difficult. The exploit has been made public and could be used.

Affected products

  • Tenda AX12 Pro Firmware: version 16.03.49.24_cn only

Published 2026-01-29. Last modified 2026-06-17.